When implementing a permission classification for applications that integrate with a Microsoft Entra tenant, which type of permissions should be included?
Choose an answer
Tap an option to check your answer.
Correct answer: delegated permissions that require only user consent.
Why this is the answer
Delegated permissions that require only user consent are crucial for applications that act on behalf of a signed-in user. This classification allows users to grant an application specific permissions to access their data within the tenant, without requiring an administrator's approval. This is ideal for less sensitive operations, promoting user autonomy and streamlining application integration. App-only access permissions, whether requiring admin or user consent, are incorrect because they are for applications acting independently, not on behalf of a user. Delegated permissions requiring admin consent are for more sensitive operations where an administrator must explicitly approve the application's access to organizational data, which is a different classification than what the question is asking for.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed