Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium

A development team is building a new multi-tenant SaaS application that needs to access user profiles and read calendar events from Microsoft Graph for users across various customer tenants. The application will primarily run as a background service without a signed-in user. Which type of permission and permission consent model should the application use?

  1. ADelegated permissions with admin consent
  2. BApplication permissions with user consent
  3. CDelegated permissions with user consent
  4. DApplication permissions with admin consent
Show answer & explanation

Correct answer: D. Application permissions with admin consent

Since the application runs as a background service without a signed-in user, it requires 'Application permissions'. Because it's a multi-tenant application accessing sensitive data (calendar events), 'admin consent' is necessary to grant these permissions across customer tenants.

Why the other options are wrong

  • A. Delegated permissions act on behalf of a user, which is not applicable for a background service without a signed-in user.
  • B. Application permissions are correct, but user consent is generally not sufficient for application permissions, especially for multi-tenant scenarios and sensitive data like calendar events, as only administrators can grant these permissions tenant-wide.
  • C. Delegated permissions are for scenarios where a user is signed in. User consent is typically for less privileged permissions or single-tenant apps.

Microsoft Graph Permissions (Application vs. Delegated)

Microsoft Graph uses two main types of permissions: Delegated permissions (on behalf of a user) and Application permissions (as the application itself). Consent can be user consent or admin consent.

  • Delegated: Requires a signed-in user, permissions are the intersection of user's and app's.
  • Application: No signed-in user, app acts as itself, often requires admin consent.
  • Admin consent: Required for application permissions and high-privilege delegated permissions in multi-tenant apps.

Memory trick: Application works alone, Delegated acts with a person.

More Implement an authentication and access management solution questions