AZ-500 exam dumps

AZ-500 practice question 35 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 35

Single answer

Your company has developed an internal multi-tenant application that is registered in Azure AD to read user profiles via Microsoft Graph using 'User.Read.All' delegated permission. During testing, users see an 'Admin consent required' prompt because your organization restricts user consent for applications. You need to grant the necessary permission for all users to use the application without changing the restricted user consent setting for all apps. What should you do?

  1. A

    Enable user consent for all applications so each user can grant 'User.Read.All' themselves.

  2. B

    Grant admin consent for the 'User.Read.All' delegated permission at the application level in Azure AD.

  3. C

    Remove the 'User.Read.All' permission from the Azure AD app registration to bypass admin consent.

  4. D

    Delegate consent via an OAuth 2.0 device code flow to automatically bypass admin approval.

Show answer and explanation

Correct answer: B

Explanation

When an application needs delegated permissions that require admin consent and user consent is restricted, the best practice is to grant admin consent specifically for the required permissions at the Azure AD app registration level. This allows all users to utilize the application’s functionality without inappropriately broadening user consent privileges. For more details, see Microsoft Documentation on 'Grant tenant-wide admin consent to an application.'

  • A. Incorrect.

    Option 1: Enabling user consent for all applications can undermine security. This approach would allow end users to grant potentially high-privilege permissions to any application without administrator oversight.

  • B. Correct.

    Option 2: Granting admin consent for 'User.Read.All' at the Azure AD app registration level meets the permission requirement for the application without relaxing the organization-wide user consent policy. This is the recommended approach.

  • C. Incorrect.

    Option 3: Removing the permission would prevent the application from performing the required operations on user profiles, defeating the purpose of the permission.

  • D. Incorrect.

    Option 4: The device code flow does not eliminate the need for admin consent to privileged permissions. It simply provides an alternative authentication method, so admin approval is still necessary.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam