Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You are registering a custom web API named api1 in Microsoft Entra ID for the contoso.com tenant. The API must be callable by client applications that reside in other Azure AD tenants. You expose a delegated permission scope named access_as_user. To ensure those external client applications can obtain OAuth 2.0 tokens for this scope, which additional setting should you configure on the api1 app registration?

  • Change Supported account types to "Accounts in any organizational directory (Any Azure AD tenant)".

  • Add a client secret to the app registration and share it with the external developers.

  • Mark the access_as_user scope as "admin consent required".

  • Enable the AllowPublicClient setting on the Authentication blade.

Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot