Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard

A company is implementing a new application that uses the OAuth 2.0 authorization code flow to obtain access tokens for accessing a protected API. The application is registered in Azure AD. Which of the following is a critical security best practice for handling the client secret in this flow?

  1. AUse a certificate instead of a client secret for confidential client applications.
  2. BHard-code the client secret into the mobile application's source code for direct API calls.
  3. CStore the client secret directly in the client-side JavaScript code of the web application.
  4. DEmbed the client secret in the redirect URI when performing the authorization request.
Show answer & explanation

Correct answer: A. Use a certificate instead of a client secret for confidential client applications.

For confidential client applications (like web apps or APIs that can securely store credentials), using a certificate for client authentication is a more secure alternative to client secrets. Certificates are harder to compromise than strings of text, especially if they are managed securely in a Key Vault or by managed identities.

Why the other options are wrong

  • B. Hard-coding client secrets in mobile app source code is insecure for the same reason as client-side JavaScript.
  • C. Storing client secrets in client-side code (public clients) is highly insecure as they can be easily extracted.
  • D. Embedding client secrets in the redirect URI is highly insecure as it would expose the secret in browser history, logs, and potentially network sniffers.

OAuth 2.0 Client Authentication

The process by which a client application proves its identity to the authorization server when requesting tokens.

  • Public clients (e.g., SPA, mobile) cannot securely store secrets.
  • Confidential clients (e.g., web apps, servers) can securely store secrets.
  • Methods include client secret (shared secret), client assertion (JWT signed with certificate), or managed identities.

Memory trick: Secrets need strong vaults, not open windows.

More Implement an authentication and access management solution questions