Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium
A development team is building a new multi-tenant SaaS application that needs to access user profiles and read calendar events from Microsoft Graph for users across various customer tenants. The application will primarily run as a background service without a signed-in user. Which type of permission and permission consent model should the application use?
- ADelegated permissions with admin consent
- BApplication permissions with user consent
- CDelegated permissions with user consent
- DApplication permissions with admin consent
Show answer & explanationAnswer & explanation
Correct answer: D. Application permissions with admin consent
Since the application runs as a background service without a signed-in user, it requires 'Application permissions'. Because it's a multi-tenant application accessing sensitive data (calendar events), 'admin consent' is necessary to grant these permissions across customer tenants.
Why the other options are wrong
- A. Delegated permissions act on behalf of a user, which is not applicable for a background service without a signed-in user.
- B. Application permissions are correct, but user consent is generally not sufficient for application permissions, especially for multi-tenant scenarios and sensitive data like calendar events, as only administrators can grant these permissions tenant-wide.
- C. Delegated permissions are for scenarios where a user is signed in. User consent is typically for less privileged permissions or single-tenant apps.
Microsoft Graph Permissions (Application vs. Delegated)
Microsoft Graph uses two main types of permissions: Delegated permissions (on behalf of a user) and Application permissions (as the application itself). Consent can be user consent or admin consent.
- Delegated: Requires a signed-in user, permissions are the intersection of user's and app's.
- Application: No signed-in user, app acts as itself, often requires admin consent.
- Admin consent: Required for application permissions and high-privilege delegated permissions in multi-tenant apps.
Memory trick: Application works alone, Delegated acts with a person.