AZ-500 exam dumps

AZ-500 practice question 26 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 26

Single answer

Your company recently added an enterprise application in Microsoft Entra ID (Azure AD) that requires delegated Graph permissions, including 'User.Read.All', which requires administrator consent. By default, users can grant certain permissions themselves. However, you need to ensure only administrators can grant the 'User.Read.All' permission to the application and that regular users cannot consent to risky permissions. What is the best way to achieve this?

  1. A

    A. Enable the 'User consent for apps' setting to 'All users can consent' in Microsoft Entra ID and rely on user training.

  2. B

    B. Disable user consent globally by setting 'User consent for apps' to 'Do not allow user consent,' then grant the required permissions through admin consent.

  3. C

    C. Create a new Conditional Access policy that restricts all delegated permissions to admins only.

  4. D

    D. Remove the 'User.Read.All' permission and require users to sign in with personal Microsoft accounts instead.

Show answer and explanation

Correct answer: B

Explanation

Azure AD (Microsoft Entra ID) provides granular control over how permissions are granted to applications. For delegated permissions that require admin consent, you can restrict end-user consent by setting 'User consent for apps' to 'Do not allow user consent' and manually granting permissions as an administrator. This approach ensures that only privileged individuals can approve high-level permissions like 'User.Read.All.' Refer to Microsoft’s documentation on app consent policies and permissions (https://learn.microsoft.com/en-us/azure/active-directory/develop/v2-permissions-and-consent) for further guidance.

  • A. Incorrect.

    Option A: Incorrect. Allowing all users to consent to apps leaves the organization vulnerable if users grant excessive privileges unintentionally. Relying solely on training can be risky for sensitive permissions such as 'User.Read.All.'

  • B. Correct.

    Option B: Correct. By disabling user consent, you ensure that only administrators can grant this permission. The 'User.Read.All' permission explicitly requires admin consent, so the best practice is to turn off user consent and have an administrator grant the permissions the application needs.

  • C. Incorrect.

    Option C: Incorrect. While Conditional Access policies can control access scenarios (e.g., location or device), they do not inherently manage or restrict permission consent for specific OAuth grants. A Conditional Access policy cannot override admin-consent-required permissions in Microsoft Entra ID.

  • D. Incorrect.

    Option D: Incorrect. Removing 'User.Read.All' might break the application’s functionality if it truly needs that permission. Requiring personal Microsoft accounts also does not address the consent model in a corporate multi-tenant environment.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam