exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 42 discussion

Actual exam question from Microsoft's AZ-500
Question #: 42
Topic #: 2
[All AZ-500 Questions]

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1.
You plan to publish several apps in the tenant.
You need to ensure that User1 can grant admin consent for the published apps.
Which two possible user roles can you assign to User1 to achieve this goal? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. Security administrator
  • B. Cloud application administrator
  • C. Application administrator
  • D. User administrator
  • E. Application developer
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
arunjana
Highly Voted 3 years, 8 months ago
Granting tenant-wide admin consent requires you to sign in as Global Administrator, an Application Administrator, or a Cloud Application Administrator.
upvoted 64 times
...
deegadaze1
Highly Voted 3 years, 5 months ago
in exam
upvoted 16 times
...
stonwall12
Most Recent 1 week, 3 days ago
Selected Answer: BC
Answer: 1. B, Cloud application administrator 2. C, Application administrator 1. The Cloud application administrator role has permissions to create and manage all aspects of enterprise applications, application registrations, and application proxy settings. Most importantly, this role can grant admin consent for delegated permissions and application permissions, which is exactly what's needed for User1. 2. The Application administrator role has similar permissions to the Cloud application administrator. It can manage all aspects of applications and service principals, including the ability to grant admin consent for the tenant, which matches the requirement for User1. Reference: 1. https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#cloud-application-administrator 2. https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#application-administrator
upvoted 1 times
...
scottyboy23
4 months, 1 week ago
on exam BC 13/04/24
upvoted 6 times
...
brooklyn510
7 months, 3 weeks ago
On exam 1/2/24
upvoted 3 times
...
yonie
8 months ago
Selected Answer: BC
To grant tenant-wide admin consent, you need: A Microsoft Entra user account with *one of the following roles*: Global Administrator or Privileged Role Administrator, for granting consent for apps requesting any permission, for any API. Cloud Application Administrator or Application Administrator, for granting consent for apps requesting any permission for any API, except Microsoft Graph app roles (application permissions). A custom directory role that includes the permission to grant permissions to applications, for the permissions required by the application. https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/grant-admin-consent?pivots=portal#prerequisites
upvoted 2 times
...
tweleve
10 months, 2 weeks ago
In exam 13 Oct
upvoted 3 times
...
Self_Study
1 year ago
On exam 7/8/23. A bit different answers to choose from.
upvoted 2 times
...
AzureAdventure
1 year ago
Cloud APPLICATION Administrator APPLICATION Administrator
upvoted 1 times
...
AzureAdventure
1 year ago
https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent?pivots=portal#:~:text=An%20Azure%20AD,by%20the%20application.
upvoted 1 times
...
ESAJRR
1 year, 1 month ago
Selected Answer: BC
B. Cloud application administrator C. Application administrator
upvoted 1 times
...
zellck
1 year, 3 months ago
Selected Answer: BC
BC is the answer. https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent?pivots=portal#prerequisites Granting tenant-wide admin consent requires you to sign in as a user that is authorized to consent on behalf of the organization. To grant tenant-wide admin consent, you need: An Azure AD user account with one of the following roles: - Global Administrator or Privileged Role Administrator, for granting consent for apps requesting any permission, for any API. - Cloud Application Administrator or Application Administrator, for granting consent for apps requesting any permission for any API, except Azure AD Graph or Microsoft Graph app roles (application permissions). - A custom directory role that includes the permission to grant permissions to applications, for the permissions required by the application.
upvoted 1 times
...
Johnvic
1 year, 4 months ago
Exam.6 case studies. 3 true/false questions. 47 multiple questions and no simulations. Alot of new questions thats not up here
upvoted 1 times
...
Gesbie
1 year, 4 months ago
In Exam April 11, 2023
upvoted 4 times
...
majstor86
1 year, 5 months ago
Selected Answer: BC
B. Cloud application administrator C. Application administrator
upvoted 3 times
...
sofieejo
1 year, 6 months ago
In exam 29/01/2023 + many questions about Microsoft Sentinel
upvoted 1 times
...
Sweet_co
2 years, 1 month ago
On my exam today: 20-7-2022
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago