Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your tenant currently blocks user consent to enterprise applications. A verified-publisher SaaS app needs only the Microsoft Graph delegated permission User.Read. Users should be able to grant that permission themselves, while any other permissions or apps from unverified publishers must still require administrator consent. Which user-consent setting in the Microsoft Entra admin center meets this requirement?
Block user consent and use a Conditional Access policy that requires user consent for the SaaS app.
Allow user consent for apps from verified publishers, for selected permissions.
Assign the Cloud Application Administrator role to the SaaS application's service principal.
Selecting "Allow user consent for apps from verified publishers, for selected permissions" lets users consent only when two conditions are met: the application's publisher is verified and it requests a permission on the low-impact list (which includes User.Read by default). Requests for additional permissions or from unverified publishers are blocked and routed to the admin consent workflow, preserving organizational security. The other options either grant overly broad consent, rely on Conditional Access (which does not control OAuth consent), or assign a role that does not influence end-user consent.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of the User.Read permission in Microsoft Graph?
Open an interactive chat with Bash
What does 'verified publisher' mean in the context of SaaS applications?
Open an interactive chat with Bash
What is the low-impact permissions list, and why is it important?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .