Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A new web application is being developed that needs to authenticate users and access data from Microsoft Graph (e.g., read user profiles, send emails). The application is hosted on an Azure App Service. The development team wants to ensure that the application only requests the minimum necessary permissions from users and adheres to the principle of least privilege. What type of permissions should the application primarily request for user-driven actions?

  1. AElevated permissions.
  2. BAdmin consent permissions.
  3. CDelegated permissions.
  4. DApplication permissions.
Show answer & explanation

Correct answer: C. Delegated permissions.

Delegated permissions are used when an application acts on behalf of a signed-in user. The application can only access what the user has permission to access, and only if the user (or an administrator) has consented. This aligns with the principle of least privilege for user-driven actions.

Why the other options are wrong

  • A. Elevated permissions is a general term and not a specific type of permission in Azure AD or Microsoft Graph context.
  • B. Admin consent permissions typically refer to specific delegated or application permissions that require an administrator to grant consent, often for broader access or for all users in a tenant.
  • D. Application permissions are used when an application acts as its own identity without a user signed in, often requiring administrator consent, and can grant broad access.

Delegated Permissions (Microsoft Graph)

Permissions that allow an application to act on behalf of a signed-in user, accessing resources that the user has permission to access, subject to user or administrator consent.

  • Application acts as the signed-in user.
  • Access is limited by the user's permissions.
  • Requires user or administrator consent.

Memory trick: Delegated: 'On behalf of me', the user's access is the key.

More Implement and manage workload identities questions