Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Within the Microsoft Entra ID tenant, you have an enterprise application representing a third-party SaaS. The vendor requests that the application be granted the Microsoft Graph delegated permission Directory.Read.All. You must ensure that users cannot consent to this permission but that an administrator can review and approve the request when needed. Which configuration should you implement?
Grant tenant-wide admin consent for Directory.Read.All in the application's API permissions page.
Disable user consent for applications and enable the Admin consent workflow in Entra ID.
Create a Conditional Access policy that requires users to accept terms of use when accessing the application.
Assign the Cloud Application Administrator role to all users who will use the application.
Disabling user consent prevents end users from approving high-privilege permissions such as Directory.Read.All. Enabling the Admin consent workflow means that when the application requests a permission requiring admin approval, a request is routed to designated reviewers who can evaluate and grant the permission. Simply granting tenant-wide consent would bypass review, assigning privileged roles to users does not control OAuth consent, and Conditional Access policies do not govern OAuth permission grant processes.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Admin consent workflow in Microsoft Entra ID?
Open an interactive chat with Bash
What does the Directory.Read.All permission in Microsoft Graph mean?
Open an interactive chat with Bash
Why is disabling user consent for applications important for security?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .