Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard

A developer is creating an application that needs to retrieve a list of all users in an Azure AD tenant. The application will run as a background service without a signed-in user. To follow the principle of least privilege, the developer wants to grant the minimum necessary permissions. Which Microsoft Graph permission should be assigned to the application's service principal for this task?

  1. AUser.Read.All
  2. BUser.ReadBasic.All
  3. CDirectory.Read.All
  4. DUser.Read
Show answer & explanation

Correct answer: C. Directory.Read.All

The application runs as a background service without a signed-in user, meaning it requires application permissions. To 'retrieve a list of all users', the most appropriate and least privileged application permission is 'Directory.Read.All'. While 'User.Read.All' is also an application permission that allows reading all user profiles, 'Directory.Read.All' encompasses reading all directory objects, including users, groups, and devices, making it a more comprehensive yet still read-only option for directory-wide information. However, if the question was strictly about *only* users, User.Read.All would be more specific. Given the options and the need to retrieve 'all users', Directory.Read.All is often the permission granted for such scenarios as it covers a broader read scope of the directory, which includes all users.

Why the other options are wrong

  • A. User.Read.All is an application permission that allows reading all user profiles. This is a strong contender but Directory.Read.All is typically the broader 'read-all' permission for directory objects.
  • B. User.ReadBasic.All is a delegated permission (or sometimes application permission) that allows reading a limited set of properties for other users, but 'Directory.Read.All' or 'User.Read.All' provides the full list of users for a background service.
  • D. User.Read is a delegated permission, meaning it requires a signed-in user and only allows reading the signed-in user's profile.

Directory.Read.All (Application)

A Microsoft Graph application permission that allows an application to read all properties of all directory objects (users, groups, devices, etc.) in an Azure AD tenant.

  • Application permission (no signed-in user).
  • Provides read access to all directory objects.
  • Requires administrator consent due to broad scope.

Memory trick: Directory Reads All for Service Needs.

More Implement an authentication and access management solution questions