Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You register an app named FinanceAPI in Microsoft Entra ID and expose a delegated permission scope named "read.invoices". You need to ensure that only two internal client applications can ever obtain access tokens that include the read.invoices scope. All other apps, even if a user or administrator tries to grant consent, must be prevented from receiving that scope.
Which statement accurately describes what you can achieve using built-in FinanceAPI app-registration settings?
Changing the Who can consent setting of the scope to Admins only prevents other apps from ever receiving the scope.
No built-in setting can enforce this for delegated permissions; you must implement custom logic in the API or use external controls.
Adding the two client IDs to the Authorized client applications list blocks all other apps from receiving the scope.
Disabling the scope and replacing it with an app role assigned only to the two apps enforces the requirement without code changes.
Microsoft Entra ID does not provide a native setting in the Expose an API blade to limit a delegated permission scope to a fixed set of client applications. The Authorized client applications list only removes the interactive consent prompt for the listed apps; it does not block other apps from requesting or receiving the scope after consent is granted. To meet the requirement, you must add custom authorization logic in the FinanceAPI code (for example, by checking the azp or appid claim and rejecting unknown client IDs) or use Conditional Access or other external controls.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the azp or appid claim in Microsoft Entra ID?
Open an interactive chat with Bash
What is Conditional Access in Microsoft Entra ID?
Open an interactive chat with Bash
How does the Authorized client applications list work in the Expose an API blade?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .