Before deploying an application that will modify Azure AD user properties via Microsoft Graph, what should you configure first so the app can access Azure AD?
Choose an answer
Tap an option to check your answer.
Correct answer: An app registration.
Why this is the answer
An app registration is the correct first step because it creates an identity for your application within Azure AD, allowing it to authenticate and be authorized to access resources like Microsoft Graph. This registration defines the application's properties, including its permissions and authentication methods. An external identity is incorrect because it refers to users from other Azure AD tenants or identity providers, not the application itself. A custom RBAC role is also incorrect; while roles define permissions, the application first needs an identity (via app registration) before it can be assigned any roles. An Azure AD Application Proxy is used to provide secure remote access to on-premises web applications, which is unrelated to an application accessing Azure AD via Microsoft Graph.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed