App1 is registered in Azure AD. You need App1 to access Azure Key Vault secrets on behalf of application users. What permission configuration is required?
Choose an answer
Tap an option to check your answer.
Correct answer: a delegated permission without admin consent.
Why this is the answer
A delegated permission without admin consent is correct because App1 needs to access resources (Key Vault secrets) on behalf of a signed-in user. This is the definition of a delegated permission. Since the access is on behalf of the user, and the user is already authenticated, admin consent is not strictly required unless the specific permission itself is highly privileged or configured to require it. An application permission would grant App1 direct access without a user context, which is not what's requested. Requiring admin consent for a delegated permission would be an unnecessary hurdle if the permission isn't highly privileged.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed