Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

An organization is deploying a new web application in Azure that will display user-specific data from Microsoft Graph API. The application needs to authenticate users and then obtain an access token to call Microsoft Graph on behalf of the user. The application itself will handle user interaction and token storage securely. Which OAuth 2.0 grant flow is most appropriate for this scenario?

  1. AResource Owner Password Credentials Grant
  2. BImplicit Grant Flow
  3. CAuthorization Code Flow with PKCE
  4. DClient Credentials Grant
Show answer & explanation

Correct answer: C. Authorization Code Flow with PKCE

The Authorization Code Flow with Proof Key for Code Exchange (PKCE) is the recommended and most secure OAuth 2.0 grant flow for public and confidential clients, especially single-page applications (SPAs) and mobile/desktop apps, as well as traditional web applications. It provides authentication for the user and then securely obtains an access token for delegated access to APIs like Microsoft Graph on behalf of the user, mitigating risks associated with token leakage.

Why the other options are wrong

  • A. Resource Owner Password Credentials Grant requires the application to handle user credentials, which is highly insecure and strongly discouraged.
  • B. Implicit Grant Flow is less secure and deprecated for most modern applications due to risks of token leakage; it is no longer recommended.
  • D. Client Credentials Grant is for server-to-server communication where there is no user context, not for applications acting on behalf of a user.

OAuth 2.0 Authorization Code Flow with PKCE

A secure OAuth 2.0 grant flow for applications to obtain delegated access to APIs on behalf of a user, preventing code interception attacks.

  • Recommended for web, mobile, desktop apps.
  • Exchanges an authorization code for tokens.
  • PKCE protects against authorization code interception.

Memory trick: Auth Code PKCE: Always Code, Protect Keys, Control Everything.

More Manage identity and access questions