AZ-500 exam dumps

AZ-500 practice question 27 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 27

Single answer

A custom enterprise application in your Microsoft Entra tenant requires delegated permissions to read user profile data from Microsoft Graph. Users are being prompted for consent every time they access the application, and your organization's security policy states that a privileged administrator must grant the required permissions once at a tenant-wide level. How should you properly configure the application to comply with this requirement?

  1. A

    Enable self-service user consent for the delegated permissions in Microsoft Entra ID.

  2. B

    From Enterprise Applications, select the application, navigate to Permissions, and choose 'Grant admin consent' for the necessary delegated permissions.

  3. C

    Add a client secret under the App Registrations pane and assign the necessary delegated permissions automatically.

  4. D

    Create a Conditional Access policy that enforces consent for all user sign-ins to the enterprise application.

Show answer and explanation

Correct answer: B

Explanation

To grant permissions for an entire organization without each user being prompted, a privileged administrator must grant admin consent within Enterprise Applications. In Microsoft Entra ID, this is accomplished by selecting the enterprise application, navigating to its Permissions section, and clicking 'Grant admin consent' for the required permissions. This procedure ensures that all users in the tenant can access the application and its authorized scopes without repeated consent prompts. For more details, refer to Microsoft’s documentation on managing consent and permissions: https://learn.microsoft.com/azure/active-directory/develop/consent-framework.

  • A. Incorrect.

    Option 1 is incorrect because enabling self-service user consent still requires individual users to accept permissions, which does not fulfill the policy of granting consent on behalf of the entire organization.

  • B. Correct.

    Option 2 is correct. By going to Enterprise Applications and selecting 'Grant admin consent,' you can provide tenant-wide consent on behalf of all users for the delegated permissions required by the application.

  • C. Incorrect.

    Option 3 is incorrect because simply adding a client secret does not automatically grant permissions. Client secrets are used to authenticate the application, not to apply admin consent for delegated permissions.

  • D. Incorrect.

    Option 4 is incorrect because a Conditional Access policy governs sign-in conditions and MFA requirements, not the delegation of admin consent for enterprise applications.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam