Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium
A developer is creating an Azure Function that needs to authenticate to Microsoft Graph to retrieve group membership information. The security team insists that the Azure Function should use the OAuth 2.0 client credentials flow to authenticate as itself, without a user context. Which type of permission should be granted to the Azure Function's identity?
- AEffective permissions.
- BUser impersonation permissions.
- CDelegated permissions.
- DApplication permissions.
Show answer & explanationAnswer & explanation
Correct answer: D. Application permissions.
The OAuth 2.0 client credentials flow is used when an application needs to authenticate as itself (a 'daemon' or 'service' application), without a user present. In this scenario, the application requires 'Application permissions' to Microsoft Graph, allowing it to access data directly with its own identity, not on behalf of a user.
Why the other options are wrong
- A. Effective permissions are the combined permissions after evaluating all assignments, not a type of permission that can be granted directly.
- B. User impersonation is a concept related to delegated permissions where the application acts as the user, which is not desired here.
- C. Delegated permissions are used when an application acts on behalf of a signed-in user. This contradicts the 'authenticate as itself, without a user context' requirement.
Application Permissions (Microsoft Graph)
Permissions granted directly to an application's identity (service principal) in Azure AD, allowing the application to access Microsoft Graph data as itself, typically used with the client credentials OAuth 2.0 flow.
- Application acts as a daemon or service.
- No user context involved in the authentication.
- Requires administrator consent.
- Used for background services accessing data.
Memory trick: Applications Act Alone, Users Delegate Data.