AZ-500 exam dumps

AZ-500 practice question 34 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 34

Single answer

You have registered a new multi-tenant application in Azure Active Directory (Azure AD) that requests both basic read permissions, such as User.Read, and elevated permissions, such as Directory.Read.All. You want end users to be able to grant consent for the basic read permission themselves, but require an administrator to approve the elevated permission. Which setting should you configure in Azure AD to achieve this?

  1. A

    Set 'Users can consent to apps accessing company data on their behalf' to 'Yes' in the Enterprise Applications > User Settings blade.

  2. B

    Set 'Users can consent to apps accessing company data on their behalf' to 'Limited' in the Enterprise Applications > User Settings blade.

  3. C

    Set 'Users can consent to apps accessing company data on their behalf' to 'No' in the Enterprise Applications > User Settings blade.

  4. D

    Remove the elevated permission from the application manifest and only request non-elevated scopes.

Show answer and explanation

Correct answer: B

Explanation

In Azure AD, user consent settings can be configured to vary the level of permissions users can approve. Choosing 'Limited' enforces that any permission requiring admin consent (like Directory.Read.All) must be approved by an administrator. This matches real-world best practices, ensuring strong governance over elevated permissions while still allowing end users to self-consent for less privileged permissions. For more details, see Microsoft Docs: https://learn.microsoft.com/azure/active-directory/manage-apps/configure-user-consent

  • A. Incorrect.

    Option 1 is incorrect. Setting 'Yes' would allow users to consent to all requested permissions, including those that require admin consent.

  • B. Correct.

    Option 2 is correct. Setting user consent to 'Limited' allows users to grant consent for non-elevated permissions while blocking permissions that require admin consent, such as Directory.Read.All.

  • C. Incorrect.

    Option 3 is incorrect. Setting 'No' completely prevents users from granting consent to any permissions. You would lose the ability for users to self-consent for basic permissions.

  • D. Incorrect.

    Option 4 is incorrect. While removing elevated permissions would bypass the need for admin consent, it defeats the requirement to keep elevated permissions available for administrative approval.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam