exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 44 discussion

Actual exam question from Microsoft's AZ-500
Question #: 44
Topic #: 2
[All AZ-500 Questions]

You have an Azure subscription that contains an Azure Active Directory (Azure AD) tenant and a user named User1.
The App registrations settings for the tenant are configured as shown in the following exhibit.

You plan to deploy an app named App1.
You need to ensure that User1 can register App1 in Azure AD. The solution must use the principle of least privilege.
Which role should you assign to User1?

  • A. App Configuration Data Owner for the subscription
  • B. Managed Application Contributor for the subscription
  • C. Cloud application administrator in Azure AD
  • D. Application developer in Azure AD
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SIDNASIR
Highly Voted 3 years, 8 months ago
Correct Answer Application Developer Users in this role can create application registrations when the "Users can register applications" setting is set to No. https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#application-developer
upvoted 32 times
...
Amin_7
Highly Voted 3 years, 8 months ago
Application Developer - Create application registration when ability is disabled for all users
upvoted 11 times
...
stonwall12
Most Recent 1 week, 3 days ago
Selected Answer: D
Answer: D, Application developer in Azure AD Reason: Since App registrations are set to "No" in the tenant settings, users by default cannot register applications. The Application developer role in Azure AD is specifically designed to allow users to register applications while following the principle of least privilege. Reference: https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#application-developer
upvoted 1 times
...
xRiot007
6 months, 2 weeks ago
Answer is D - app developer. It's so annoying that all these options are so interlaced creating a lot of times confusion. In this case, MS should remove such flags so that all controls are centralized around roles. This would make things clear in a lot of cases.
upvoted 4 times
...
ESAJRR
1 year, 7 months ago
Selected Answer: D
D. Application developer in Azure AD
upvoted 1 times
...
zellck
1 year, 9 months ago
Selected Answer: D
D is the answer. https://learn.microsoft.com/en-us/azure/active-directory/roles/delegate-app-roles#grant-individual-permissions-to-create-and-consent-to-applications-when-the-default-ability-is-disabled Assign the Application Developer role to grant the ability to create application registrations when the Users can register applications setting is set to No. This role also grants permission to consent on one's own behalf when the Users can consent to apps accessing company data on their behalf setting is set to No.
upvoted 2 times
...
r_git
1 year, 11 months ago
Selected Answer: D
D is correct Users in this role can create application registrations when the "Users can register applications" setting is set to No. https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#application-developer
upvoted 2 times
...
majstor86
1 year, 11 months ago
Selected Answer: D
D. Application developer in Azure AD
upvoted 4 times
...
samimshaikh
2 years ago
By default, any user in Azure AD cannot register applications. The ability to register applications in Azure AD is typically restricted to administrators or users with specific permissions. However, the level of access control for application registration can be configured by an administrator through the use of Azure AD role-based access control (RBAC). For example, an administrator can grant specific users or groups the ability to register applications in Azure AD by assigning them the "Application Developer" role. In summary, t The ability to register applications in Azure AD is not available to all users by default but can be granted through the use of Azure AD RBAC. D is correct considering least priviledged
upvoted 1 times
...
Sir_Learnalot
2 years, 1 month ago
Selected Answer: D
Application Developer is the least privilege option here
upvoted 2 times
...
ltjones12
2 years, 1 month ago
Correct. To register an app you need app developer. To grant consent to an app you need with app admin or cloud app admin.
upvoted 1 times
...
KaleMu92
2 years, 2 months ago
In Exam 02/12/2022. 3 new questions, rest from here.
upvoted 4 times
...
promto
2 years, 4 months ago
Selected Answer: D
correct
upvoted 2 times
...
somenick
2 years, 4 months ago
Selected Answer: D
correct: https://learn.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task
upvoted 3 times
...
joanjcanals
2 years, 4 months ago
Selected Answer: D
correct: https://learn.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task
upvoted 2 times
...
badrmotayeb
2 years, 6 months ago
Application Developer Can create application registrations independent of the 'Users can register applications' setting. https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
upvoted 3 times
...
luckflying
2 years, 6 months ago
Selected Answer: C
Please check the additional roles, the Cloud App Admin role is the right selection. https://docs.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago