Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard

A developer is creating an Azure Function that needs to authenticate to Microsoft Graph to read user profiles (User.Read.All). The function will run without a signed-in user (i.e., as a daemon process). The security team requires that the application only be granted application permissions, not delegated permissions. Which type of permission should the developer request in the Azure AD application registration?

  1. AApplication permissions for User.Read.All
  2. BDelegated permissions for User.Read.All
  3. CApplication permissions for User.Read
  4. DDelegated permissions for User.Read
Show answer & explanation

Correct answer: A. Application permissions for User.Read.All

Since the function runs as a daemon process (without a signed-in user), it cannot use delegated permissions. Instead, it must be granted application permissions directly. 'User.Read.All' is the correct permission scope to read all user profiles in the directory, as specified by the requirement.

Why the other options are wrong

  • B. Delegated permissions require a signed-in user context. A daemon process does not have a user context.
  • C. While 'Application permissions' is correct, 'User.Read' only allows reading the application's own profile or a limited scope, not 'all' user profiles as required.
  • D. Delegated permissions are incorrect for a daemon process. User.Read only allows reading the signed-in user's profile, not 'all' user profiles.

Application Permissions (Microsoft Graph)

Permissions granted directly to an application, allowing it to act as its own identity and access resources without a signed-in user.

  • Used by daemon applications or services (e.g., background services, Azure Functions).
  • Application acts on its own behalf.
  • Requires administrator consent.
  • Often provides broad access (e.g., .Read.All, .Write.All).

Memory trick: Daemon's direct access: Application permissions, no user needed.

More Implement and manage workload identities questions