Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium
A company is developing a new mobile application that will access an Azure API Management (APIM) instance. The mobile application needs to authenticate users and then use the resulting token to access the API. Which authentication method should the mobile application use to acquire the token from Azure AD?
- AClient Credentials flow (OAuth 2.0)
- BAuthorization Code flow with PKCE (Proof Key for Code Exchange)
- CResource Owner Password Credentials (ROPC) flow (OAuth 2.0)
- DImplicit flow (OAuth 2.0)
Show answer & explanationAnswer & explanation
Correct answer: B. Authorization Code flow with PKCE (Proof Key for Code Exchange)
For public clients like mobile applications, the Authorization Code flow with PKCE (Proof Key for Code Exchange) is the recommended and most secure OAuth 2.0 flow. PKCE mitigates the risk of authorization code interception, which is a concern in environments where the client secret cannot be securely stored.
Why the other options are wrong
- A. Client Credentials flow is for server-to-server and does not involve a user.
- C. ROPC flow requires the application to handle user credentials directly, which is highly insecure and not recommended for any client type.
- D. Implicit flow is less secure and deprecated for new mobile applications due to token leakage risks and lack of refresh tokens.
OAuth 2.0 Authorization Code Flow with PKCE
An enhanced Authorization Code flow that adds a Proof Key for Code Exchange (PKCE) to mitigate authorization code interception attacks, making it suitable for public clients like mobile and single-page applications (SPAs).
- Recommended for public clients (mobile, SPA)
- Protects against authorization code interception
- Client never stores a secret
Memory trick: PKCE: Mobile's secret handshake for security.