Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionHard
A company is developing a new multi-tenant SaaS application that will be used by customers from various Azure AD tenants. The application needs to securely access Microsoft Graph API on behalf of the signed-in user to read their profile information. What permission type should the application request from Azure AD?
- ADelegated permissions (on behalf of user)
- BMicrosoft Graph administrative consent
- CAzure AD role-based access control
- DApplication permissions (app-only)
Show answer & explanationAnswer & explanation
Correct answer: A. Delegated permissions (on behalf of user)
Since the application needs to access Microsoft Graph 'on behalf of the signed-in user' to read *their* profile, it requires delegated permissions. With delegated permissions, the application acts as the user, and the permissions granted are limited by both the application's consented permissions and the user's actual permissions to the resource.
Why the other options are wrong
- B. Microsoft Graph administrative consent is a mechanism for IT admins to grant permissions for all users in a tenant, but it's not a permission *type* itself; it applies to either delegated or application permissions.
- C. Azure AD role-based access control (RBAC) is for managing access to Azure resources, not for defining permissions an application needs to access Microsoft Graph on behalf of a user.
- D. Application permissions are for scenarios where the application acts as itself (no user involved) and needs to access data without a signed-in user, which is not the case here.
Microsoft Graph Permission Types
The two main types of permissions an application can request to access Microsoft Graph: delegated (on behalf of a user) and application (app-only).
- Delegated permissions require a signed-in user.
- Application permissions allow the app to act independently.
- Both require admin or user consent, depending on the permission scope.
Memory trick: Graph: Who is acting, user or app?