AZ-500 exam dumps

AZ-500 practice question 24 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 24

Select 2

You are an Azure administrator managing an enterprise application in Microsoft Entra ID (Azure AD) for your organization. The application is for internal use only, and you need to ensure that only members of a specific Azure AD security group can sign in. Which two steps should you take to enforce this requirement?

  1. A

    Enable the 'User assignment required' setting on the enterprise application.

  2. B

    Enable self-service password reset (SSPR) for the security group.

  3. C

    Assign the specific Azure AD security group as a user of the enterprise application.

  4. D

    Configure a redirect URI in the app registration to point to the security group’s object ID.

  5. E

    Grant the enterprise application permission to read group memberships in Microsoft Graph.

Show answer and explanation

Correct answers: A, C

Explanation

To restrict sign-in to only members of a specific Azure AD security group, you must first enable 'User assignment required' in the enterprise application’s Properties. Next, assign the intended security group under the application's Users and groups. This combination ensures only members of the assigned group can access the app. For more details, refer to Microsoft’s documentation on assigning users and groups to an enterprise application (https://docs.microsoft.com/azure/active-directory/manage-apps/howto-manage-apps).

  • A. Correct.

    Correct. Setting 'User assignment required' on the enterprise application ensures that only assigned users (or groups) can access the app. By default, users might be able to access applications without explicit assignment unless this is enabled.

  • B. Incorrect.

    Incorrect. Enabling self-service password reset (SSPR) is unrelated to restricting access to a specific group. SSPR only helps users reset their passwords but does not control who can sign in to the enterprise application.

  • C. Correct.

    Correct. You must explicitly assign the desired security group to the enterprise application. When 'User assignment required' is enabled, only those users or groups assigned in the application's Users and groups blade can access it.

  • D. Incorrect.

    Incorrect. Configuring a redirect URI in the app registration with the group’s object ID does not restrict application access. Redirect URIs control where authentication tokens are sent, not which users have permission.

  • E. Incorrect.

    Incorrect. Granting the enterprise application permission to read group memberships in Microsoft Graph may be useful for certain functionalities, but it does not by itself enforce sign-in restrictions to a specific group.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam