Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDMedium

A company uses Microsoft Entra ID for identity management. They have a custom line-of-business application that needs to retrieve user profile information from Microsoft Entra ID. The application should only have read access to user attributes and should not be able to modify any user data. Which type of identity should you create for the application to access Microsoft Entra ID?

  1. AManaged identity
  2. BService principal with application permissions
  3. CGuest user account
  4. DUser account
Show answer & explanation

Correct answer: B. Service principal with application permissions

A service principal with application permissions is the appropriate identity type for a custom line-of-business application to access Microsoft Entra ID. You can grant it specific read-only permissions (e.g., User.Read.All) to ensure it only retrieves user profile information without modification capabilities.

Why the other options are wrong

  • A. Managed identities are for Azure resources (like VMs, App Services) to authenticate to Entra ID, not for custom external applications.
  • C. Guest user accounts are for external human users, not applications.
  • D. Using a regular user account for an application is a security anti-pattern and often violates least privilege.

Service Principal for Applications

A security identity that represents an application within a Microsoft Entra ID tenant, enabling it to access resources that are secured by Entra ID.

  • Acts as an instance of an application object in a specific tenant.
  • Can be assigned permissions (application permissions) to access Microsoft Graph or other APIs.
  • Used for daemon applications, automated scripts, or line-of-business applications.

Memory trick: Applications need Principals for Permissions.

More Implement and manage Microsoft Entra ID questions