Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A company is implementing a new policy that requires all users to provide explicit consent before any third-party application can access their Azure AD data. They want to ensure that only administrators can grant consent for applications on behalf of all users. Which Azure AD setting should be configured to achieve this?

  1. AApplication assignment required
  2. BAdmin consent workflow
  3. CConditional Access app control
  4. DUser consent for applications
Show answer & explanation

Correct answer: B. Admin consent workflow

The Admin consent workflow allows users to request administrator approval for applications that require consent. This ensures that only authorized administrators can grant tenant-wide consent, meeting the requirement for explicit admin approval.

Why the other options are wrong

  • A. Application assignment required controls who can sign into an application, not who can grant consent for it.
  • C. Conditional Access app control is for real-time monitoring and control of access to cloud apps after authentication, not for managing application consent.
  • D. Disabling 'User consent for applications' prevents users from consenting but doesn't provide a mechanism for administrators to grant consent on behalf of users; it just blocks consent.

Azure AD Admin Consent Workflow

A feature in Azure AD that enables users to request administrator approval for applications that require permissions to access company data, centralizing the consent process.

  • Users request admin approval for app consent.
  • Admins review and grant/deny consent.
  • Ensures centralized control over app access to data.

Memory trick: Admin consent workflow is like putting an 'approval required' stamp on every new app.

More Manage identity and access questions