Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard

A large enterprise has enabled an Azure AD tenant-wide setting that requires administrator consent for all applications requesting certain high-privilege delegated permissions. A new line-of-business application developed in-house requires the 'User.ReadWrite.All' delegated permission to manage user profiles. A standard user attempts to sign into this application. What will happen?

  1. AThe user will be blocked from signing in and presented with an error message indicating that admin consent is required.
  2. BThe user will be prompted for their consent, and after granting it, the application will function normally.
  3. CThe user will be able to sign in, but the application will not be able to access the 'User.ReadWrite.All' permission.
  4. DThe application will automatically be granted the 'User.ReadWrite.All' permission after the first sign-in.
Show answer & explanation

Correct answer: A. The user will be blocked from signing in and presented with an error message indicating that admin consent is required.

When an application requests a delegated permission that requires administrator consent (either because of the permission's nature or a tenant-wide setting), a standard user cannot grant that consent. They will be blocked and receive a message indicating that an administrator needs to grant consent.

Why the other options are wrong

  • B. Standard users cannot grant consent for permissions requiring administrator approval, regardless of whether the tenant has a specific setting for it or not for high-privilege permissions.
  • C. If consent is not granted for a required permission, the application generally cannot proceed with that functionality, and often the sign-in itself will fail.
  • D. Permissions are never automatically granted without explicit consent from a user or administrator, especially for high-privilege operations.

Admin Consent Flow

A process where an Azure AD administrator explicitly grants permissions to an application on behalf of all users in the tenant, typically for high-privilege permissions or when a tenant-wide setting requires it.

  • Required for application permissions.
  • Required for certain high-privilege delegated permissions.
  • Can be mandatory for all permissions based on tenant settings.

Memory trick: Admin Consent: If not the king, you can't open the door, only the admin has the power to explore.

More Implement and manage workload identities questions