Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You registered an ASP.NET Core web API named ContosoApi in Microsoft Entra ID. Background services in other Azure AD tenants will call the API by using the OAuth 2.0 client-credentials flow. Each consuming tenant's administrator must grant consent, and the API must not expose any delegated permissions.
In the Azure portal, which change should you make to the ContosoApi app registration to satisfy these requirements?
Add a delegated permission scope and set "User consent enabled" to Yes.
Add an application role that has Allowed member type set to "Application" and admin consent required enabled.
Enable the "Allow public client flows" option in Authentication settings.
Change Supported account types to "Accounts in this organizational directory only".
Background services that call an API without a signed-in user need an application permission usable with the client-credentials flow. In an app registration, such a permission is created by defining an application role whose Allowed member type is set to Application. Application permissions always require admin consent, ensuring administrators in external tenants must approve access before tokens can be issued. Delegated scopes, public-client settings, or single-tenant configurations would not meet the stated requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the OAuth 2.0 client-credentials flow?
Open an interactive chat with Bash
What is the significance of an application role in Azure AD app registration?
Open an interactive chat with Bash
Why don’t delegated permissions work in this scenario?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .