Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A developer is building a multi-tenant SaaS application that needs to access Microsoft Graph API on behalf of signed-in users. The application requires permissions to read user profiles and send emails. To ensure the principle of least privilege, the developer wants to request only the necessary permissions. Which type of permission should the developer request for this scenario?
- ADelegated permissions
- BEffective permissions
- CAdmin consent permissions
- DApplication permissions
Show answer & explanationAnswer & explanation
Correct answer: A. Delegated permissions
Delegated permissions are used when an application acts on behalf of a signed-in user. The application will have access to what the user has access to, limited by the permissions granted to the application. This aligns with the requirement for the SaaS application to access Microsoft Graph API 'on behalf of signed-in users' for tasks like reading profiles and sending emails.
Why the other options are wrong
- B. Effective permissions are the actual permissions an application has at runtime, which is a combination of delegated permissions and the user's permissions, not a type of permission to request.
- C. Admin consent permissions are a mechanism for an administrator to grant permissions on behalf of all users in a tenant, but 'admin consent' itself is not a type of permission, rather a way to grant delegated or application permissions.
- D. Application permissions are used when an application acts on its own, without a signed-in user, typically for background services or daemons.
Delegated Permissions
Permissions used by an application to act on behalf of a signed-in user, with access limited by both the granted permissions and the user's own permissions.
- Application acts 'on behalf of' a user.
- Requires user consent (or admin consent).
- Combined scope of app permissions and user's access.
Memory trick: Delegate Users, Apply Apps.