Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesMedium

A development team is building a new web application that needs to access user-specific data in Microsoft Graph, such as calendar events and emails. The application will authenticate users directly. The security team requires that the application only accesses data on behalf of the signed-in user and never with its own identity. Which type of permission should the application request?

  1. AApplication permissions
  2. BDelegated permissions
  3. CPrivileged Access Management (PIM) permissions
  4. DAdmin consent permissions
Show answer & explanation

Correct answer: B. Delegated permissions

Delegated permissions are used when an application needs to access a resource on behalf of a signed-in user. The application will act as the user, and its effective permissions will be the intersection of the delegated permissions granted to the application and the permissions the user already has.

Why the other options are wrong

  • A. Application permissions allow an application to access data without a signed-in user, which is contrary to the requirement.
  • C. PIM is for managing just-in-time access for administrative roles, not for regular application access to user data.
  • D. Admin consent is a mechanism for granting permissions, not a type of permission itself. It can be used for both delegated and application permissions.

Delegated Permissions

Permissions that allow an application to act on behalf of a signed-in user. The application's effective permissions are the least privileged of the delegated permissions granted to the application and the permissions the user has.

  • Requires a signed-in user.
  • Application acts 'on behalf of' the user.
  • Effective permissions are the intersection of app and user permissions.

Memory trick: DELEGATED means DOING for the USER.

More Implement and manage workload identities questions