A large enterprise has enabled an Azure AD tenant-wide setting that requires administrator consent for all applications requesting certain high-privilege delegated permissions. A new line-of-business application developed in-house requires the 'User.ReadWrite.All' delegated permission to manage user profiles. A standard user attempts to sign into this application. What will happen?
- AThe user will be blocked from signing in and presented with an error message indicating that admin consent is required.
- BThe user will be prompted for their consent, and after granting it, the application will function normally.
- CThe user will be able to sign in, but the application will not be able to access the 'User.ReadWrite.All' permission.
- DThe application will automatically be granted the 'User.ReadWrite.All' permission after the first sign-in.
Show answer & explanationAnswer & explanation
Correct answer: A. The user will be blocked from signing in and presented with an error message indicating that admin consent is required.
When an application requests a delegated permission that requires administrator consent (either because of the permission's nature or a tenant-wide setting), a standard user cannot grant that consent. They will be blocked and receive a message indicating that an administrator needs to grant consent.
Why the other options are wrong
- B. Standard users cannot grant consent for permissions requiring administrator approval, regardless of whether the tenant has a specific setting for it or not for high-privilege permissions.
- C. If consent is not granted for a required permission, the application generally cannot proceed with that functionality, and often the sign-in itself will fail.
- D. Permissions are never automatically granted without explicit consent from a user or administrator, especially for high-privilege operations.
Admin Consent Flow
A process where an Azure AD administrator explicitly grants permissions to an application on behalf of all users in the tenant, typically for high-privilege permissions or when a tenant-wide setting requires it.
- Required for application permissions.
- Required for certain high-privilege delegated permissions.
- Can be mandatory for all permissions based on tenant settings.
Memory trick: Admin Consent: If not the king, you can't open the door, only the admin has the power to explore.