An application registered in Azure AD must access Azure Key Vault secrets on behalf of users. If you configure a delegated permission and grant admin consent, does this meet the requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: No.
Why this is the answer
No, this does not meet the requirement. Delegated permissions allow an application to act on behalf of a signed-in user, but they do not grant the application direct access to resources like Azure Key Vault secrets. While admin consent allows the application to access the delegated permissions for all users in the tenant, the application still needs to request specific access to Key Vault secrets through a service principal or managed identity. The application itself, not the user, needs the permission to access the Key Vault.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed