Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A software vendor is developing a new multi-tenant SaaS application that will be published to the Azure AD application gallery. The application needs to read basic user profiles (display name, email) from customer tenants' Azure AD. The vendor wants to ensure that customers can easily grant the necessary permissions without requiring a tenant administrator for every single customer. Which combination of permission type and consent model should the vendor implement?
- AApplication permissions with admin consent.
- BDelegated permissions with user consent.
- CApplication permissions with user consent.
- DDelegated permissions with admin consent.
Show answer & explanationAnswer & explanation
Correct answer: B. Delegated permissions with user consent.
To read basic user profiles for a signed-in user and allow non-admin users to grant consent, 'Delegated permissions' are appropriate, and 'user consent' is suitable for low-privilege permissions like 'User.Read'.
Why the other options are wrong
- A. Application permissions are for applications acting without a signed-in user, and admin consent is required, which violates the 'without requiring a tenant administrator' part.
- C. Application permissions are incorrect as the app acts on behalf of a user. User consent is generally not available for application permissions.
- D. While delegated permissions are correct, requiring 'admin consent' would violate the 'without requiring a tenant administrator' part of the requirement.
Microsoft Graph Consent Models
Microsoft Graph permissions utilize different consent models (user or admin) depending on the permission type (delegated or application) and the sensitivity/scope of the requested access.
- User consent: Granted by individual users for delegated permissions that don't require admin privileges.
- Admin consent: Granted by a tenant administrator for application permissions or high-privilege delegated permissions (tenant-wide).
- Delegated permissions: Act on behalf of a signed-in user.
- Application permissions: Act as the application itself, no signed-in user.
Memory trick: User acts FOR, App acts ALONE.