Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your Azure AD tenant hosts two single-tenant app registrations: FinanceAPI and FinancePortal. FinanceAPI exposes a scope named Finance.WorkItems. FinancePortal must call FinanceAPI on behalf of signed-in employees without showing individual consent prompts. What should you configure in FinancePortal's API permissions?
Add the Finance.WorkItems application permission and grant tenant-wide admin consent.
Add the Finance.WorkItems delegated permission and grant tenant-wide admin consent.
Add the Finance.WorkItems delegated permission and enable the Require user assignment setting.
Add the Finance.WorkItems application permission and leave the User consent description blank.
FinancePortal will act on behalf of the signed-in user, so it requires a delegated permission, not an application permission. To prevent users from seeing the consent dialog, an administrator can grant tenant-wide consent to that delegated scope. After admin consent is granted, all users can acquire tokens that include the Finance.WorkItems scope without being prompted individually.
Incorrect choices:
Adding an application permission would let the portal run as its own identity, ignoring the signed-in user and violating the on-behalf-of requirement.
Enabling Require user assignment does not affect the consent UX; it only controls sign-in to the app itself.
Leaving the user-consent description blank or similar UI tweaks do not suppress the consent prompt; only admin consent does.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a delegated permission in Azure AD?
Open an interactive chat with Bash
What is admin consent in Azure AD and how does it work?
Open an interactive chat with Bash
What is the difference between delegated and application permissions in Azure AD?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .