Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium

A company is developing a new API that will be consumed by several client applications. The API needs to restrict access based on the calling application's identity, not the end-user's identity. Which type of Azure Active Directory application permission should be used when registering the API and its client applications?

  1. ADelegated permissions
  2. BApplication permissions
  3. CHybrid permissions
  4. DUser permissions
Show answer & explanation

Correct answer: B. Application permissions

Application permissions are used when a client application needs to access an API directly as itself, without a signed-in user. The client application is granted these permissions, and it presents its own identity (e.g., client ID and secret) to Azure AD to obtain an access token.

Why the other options are wrong

  • A. Delegated permissions are used when an application acts on behalf of a signed-in user, which is contrary to the requirement.
  • C. Hybrid permissions are not a recognized type of Azure AD application permission.
  • D. User permissions are not a standard type of Azure AD application permission; permissions are typically delegated or application.

Azure AD Application Permissions

Permissions granted to an application to access an API directly, using its own identity, without a signed-in user context.

  • Used for daemon services or background processes
  • Provides application-level access to resources
  • Requires administrator consent

Memory trick: Application: The app is its own boss.

More Implement Azure security questions