Microsoft Azure Security Engineer Associate AZ-500 Practice Question

Within the Microsoft Entra ID tenant, you have an enterprise application representing a third-party SaaS. The vendor requests that the application be granted the Microsoft Graph delegated permission Directory.Read.All. You must ensure that users cannot consent to this permission but that an administrator can review and approve the request when needed. Which configuration should you implement?

  • Grant tenant-wide admin consent for Directory.Read.All in the application's API permissions page.

  • Disable user consent for applications and enable the Admin consent workflow in Entra ID.

  • Create a Conditional Access policy that requires users to accept terms of use when accessing the application.

  • Assign the Cloud Application Administrator role to all users who will use the application.

Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot