Microsoft Certified: Azure Developer Associate (AZ-204)Implement Azure securityMedium

A developer is building an ASP.NET Core web application hosted on Azure App Service. The application needs to authenticate users from a multi-tenant Azure Active Directory (AAD) tenant. Which authentication flow is most suitable for this scenario, allowing users to sign in without providing their credentials to the application directly?

  1. AClient Credentials flow
  2. BImplicit flow
  3. CAuthorization Code flow
  4. DResource Owner Password Credentials (ROPC) flow
Show answer & explanation

Correct answer: C. Authorization Code flow

The Authorization Code flow is the recommended and most secure OAuth 2.0 flow for web applications. It involves redirecting the user to the identity provider (AAD), where they authenticate, and then AAD redirects back to the application with an authorization code. The application then exchanges this code for an access token, avoiding direct credential handling.

Why the other options are wrong

  • A. Client Credentials flow is for server-to-server communication, not user authentication.
  • B. Implicit flow is less secure and generally discouraged for new applications, especially those requiring refresh tokens or handling sensitive data.
  • D. ROPC flow requires the application to handle user credentials directly, which is highly insecure and not recommended.

OAuth 2.0 Authorization Code Flow

A secure OAuth 2.0 flow for web applications where the client redirects the user to an authorization server to authenticate and authorize, receiving an authorization code which is then exchanged for an access token.

  • Recommended for confidential clients (web apps)
  • Client never sees user's credentials
  • Provides refresh tokens for long-lived sessions

Memory trick: Auth Code: The web app's secure secret handshake.

More Implement Azure security questions