Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Contoso registers a daemon application named DataSync in Microsoft Entra ID. The app's API permissions list shows Microsoft Graph application permission "Directory.Read.All" with the status Not granted for Contoso. You must ensure the permission is consented tenant-wide so DataSync can run with the client-credential flow and without any interactive prompt. Which Azure portal action should you take?

  • Add the DataSync managed identity to the built-in Directory Readers role in Microsoft Entra ID.

  • Enable the admin consent workflow and designate a reviewer group that includes the DataSync service principal.

  • Open the DataSync app registration, select API permissions, and choose Grant admin consent for Contoso.

  • In User settings, set "Users can consent to apps accessing company data on their behalf" to Yes.

Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot