nerdexam
Microsoft

AZ-500 · Question #193

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1. You plan to publish several apps in the tenant. You need to ensure that User1 can grant admin…

The correct answer is B. Cloud application administrator C. Application administrator. Explanation Cloud Application Administrator (B) and Application Administrator (C) are both correct because these roles explicitly include the permission to grant tenant-wide admin consent for applications, allowing users assigned these roles to approve the permissions requested…

Submitted by yousef_jo· Mar 6, 2026Secure identity and access

Question

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains a user named User1. You plan to publish several apps in the tenant. You need to ensure that User1 can grant admin consent for the published apps. Which two possible user roles can you assign to User1 to achieve this goal? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • ASecurity administrator
  • BCloud application administrator
  • CApplication administrator
  • DUser administrator
  • EApplication developer

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    74% (28)
  • D
    16% (6)
  • E
    8% (3)

Explanation

Explanation

Cloud Application Administrator (B) and Application Administrator (C) are both correct because these roles explicitly include the permission to grant tenant-wide admin consent for applications, allowing users assigned these roles to approve the permissions requested by published apps on behalf of the organization. Both roles are specifically designed to manage application registrations and enterprise applications, making admin consent a core part of their responsibilities.

Why the distractors are wrong:

  • Security Administrator (A) manages security policies and security-related features but does not have the ability to grant admin consent for apps.
  • User Administrator (D) manages user accounts and groups but has no application consent permissions.
  • Application Developer (E) can create app registrations even when users are restricted from doing so, but cannot grant admin consent - this role is about development, not governance.

Memory Tip

Think of it this way: if the role has "Application" in its name and deals with management (Administrator), it can grant admin consent. The key word is "Administrator" - developers build apps, administrators approve them. Both Cloud App Admin and App Admin sit above developers in the hierarchy, so they hold the consent keys.

Topics

#Azure AD Roles#Admin Consent#Application Management

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice