What to do first for certificate-based authentication in Entra ID?
Your on-premises network contains an Active Directory Domain Services (AD DS) domain and a certification authority (CA) named CA1. You have an Azure AD tenant. You need to implement certificate-based authentication in Azure AD. The solution must ensure that users can sign in by using certificates issued by CA1. What should you do first?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the prerequisite order for Entra ID certificate-based authentication (CBA), and the common trap is confusing CA trust onboarding with certificate issuance or storage tasks such as auto-enrollment or Azure Key Vault.
Implementing certificate-based authentication in Microsoft Entra ID requires the tenant to trust the issuing certification authority before users can sign in with certificates. The first action is to add CA1 as a certificate authority in Entra ID, which is option B and the confirmed answer.
Learners often choose Azure Key Vault (A) or auto-enrollment (C), assuming certificates or user enrollment must be prepared first, but Entra ID cannot validate CA1-issued certificates until CA1 is registered as a trusted certificate authority in the tenant.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Certificate-based authentication in Microsoft Entra ID works only when the tenant trusts the certification authority that issued the user certificate. Before any authentication policy, sign-in method, or user certificate mapping can function, you must add CA1 as a certificate authority in Entra ID by uploading its root certificate and certificate revocation list (CRL) and specifying the CRL distribution point. Option B is exactly that first step: adding CA1 as a Certificate Authority to the Microsoft Entra ID tenant. Once CA1 is trusted, Entra ID can validate certificates it issues and check their revocation status during sign-in. The question asks what to do first, and CA trust onboarding is the prerequisite for every later CBA configuration task.Why the Other Options Are Wrong
Option A, deploying an Azure Key Vault, is useful for storing and managing secrets or certificates used by applications, but it does not make Entra ID trust CA1 for user authentication. Option C, enabling auto-enrollment for CA1, is a certificate-issuance and lifecycle activity on the on-premises or hybrid side, and it does not register CA1 as a trusted issuer in the Entra ID tenant. Option D, deploying Windows Hello for Business, is a separate passwordless authentication method based on key pairs, not a step for accepting CA1-issued certificates in Entra ID. None of these options establishes the required certificate authority trust relationship in Entra ID.Community Comment Notes
Community voters unanimously selected B, and the reasoning aligns with the official prerequisite. As cpaljchc4 noted, Microsoft documentation requires you to "Configure at least one certification authority (CA) and any intermediate CAs in Microsoft Entra ID." Sozo explained that you need to upload the root certificate and the certificate revocation list of CA1 to Entra ID and specify the CRL distribution point so Entra ID can validate CA1-issued certificates and check revocation status. Panama469 also pointed to the Azure portal path: Entra ID, Security, Certificate Authorities, confirming that adding the CA is the first practical step.Official Reference
Exam Strategy
When an SC-300 question asks for the first step in certificate-based authentication, look for the action that establishes trust between Entra ID and the issuing CA, not the step that issues certificates to users. The tenant must trust the CA before any authentication policy or user certificate mapping can work.
Frequently Asked Questions
Why is Azure Key Vault not the first step for Entra ID certificate-based authentication?
Azure Key Vault stores and manages secrets or certificates, but it does not make Entra ID trust CA1 as an issuer. Entra ID needs CA1 registered as a certificate authority before it can validate user certificates.
Where do you add CA1 as a trusted certificate authority in Entra ID?
In the Azure portal, go to Microsoft Entra ID > Security > Certificate Authorities, then upload CA1's root certificate and CRL and configure the CRL distribution point.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →