Admin1 (assigned the Application developer role) registered a purchased cloud app App1 but cannot enable token encryption for the app in the Azure portal. What must be done so Admin1 can enable token encryption for App1?
Choose an answer
Tap an option to check your answer.
Correct answer: Upload a certificate for App1.
Why this is the answer
To enable token encryption for an application in Azure AD, a certificate must be uploaded and configured for that application. This certificate is used to encrypt the tokens issued by Azure AD for the application, enhancing security. Without a certificate, the option to enable token encryption will not be available or functional. Modifying App1's API permissions is incorrect because API permissions control what resources an application can access, not its token encryption capabilities. Adding App1 as an enterprise application is incorrect because all registered applications are, by definition, enterprise applications in Azure AD; this action wouldn't specifically enable token encryption. Assigning Admin1 the Cloud application administrator role is incorrect because the issue is a missing technical prerequisite (the certificate), not a lack of administrative permissions for Admin1. The Application developer role already has sufficient permissions to manage application properties, including uploading certificates.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed