Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are defining a new delegated permission scope named "Tasks.ReadWrite" for a single-tenant web API in the Azure portal. The permission must be grantable only after an administrator has approved it; regular users must not be able to self-consent. When you add the scope under Expose an API, which configuration change will meet the requirement?
Set the Who can consent option to Admins only when creating the Tasks.ReadWrite scope.
Add the Tasks.ReadWrite scope to the API permissions list of the Contoso API itself.
Define Tasks.ReadWrite as an application role instead of a scope because application roles always require admin consent.
Keep the default Admins and users value for Who can consent so that either can approve the permission.
To require administrator approval for a delegated permission scope, you must restrict who can grant consent. In the Expose an API blade, when you add or edit a scope, the Who can consent setting controls this behavior. Choosing Admins only prevents users from self-consenting; an administrator must grant the permission on their behalf. Adding the scope elsewhere, switching to an application role, or leaving the default Admins and users option would all allow users to consent or would create a different type of permission.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a delegated permission scope in Azure?
Open an interactive chat with Bash
Why is admin consent required for some permissions?
Open an interactive chat with Bash
What is the 'Expose an API' setting in Azure?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .