nerdexam
Microsoft

AZ-500 · Question #436

Hotspot Question You have an Azure AD tenant named contoso.com that contains the users shown in the following table. You add enterprise applications to contoso.com as shown in the following table…

This question assesses understanding of Azure AD roles, specifically who can grant admin consent for enterprise applications, and how an application's internal 'Grant admin consent setting' impacts this capability.

Submitted by fatima_kr· Mar 6, 2026Secure identity and access

Question

Hotspot Question You have an Azure AD tenant named contoso.com that contains the users shown in the following table. You add enterprise applications to contoso.com as shown in the following table. You need to identify which users can grant admin consent for App1 and App2. Which users should you identify for each application? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibit

AZ-500 question #436 exhibit

Answer Area

  • App1:
    User1 onlyUser1 and User2 onlyUser1 and User3 onlyUser1, User2 and User3 onlyUser1, User2, User3, and User4
  • App2:
    User1 onlyUser1 and User2 onlyUser1 and User4 onlyUser1, User2 and User4 onlyUser1, User2, User3, and User4

Explanation

This question assesses understanding of Azure AD roles, specifically who can grant admin consent for enterprise applications, and how an application's internal 'Grant admin consent setting' impacts this capability.

Approach. To answer this hotspot question, it's crucial to understand the permissions associated with each Azure AD role regarding application consent, and how specific application settings ('Grant admin consent setting') modify this behavior for interactive consent processes. The core concept is that Global Administrators have comprehensive control, Application Administrators have significant but not absolute control, and other roles cannot grant admin consent. The application's setting acts as a gatekeeper for the standard interactive consent flow.

Concept tested. Azure AD Role-Based Access Control (RBAC) for application management, Admin Consent in Azure AD, and the impact of enterprise application settings on consent flows.

Topics

#admin consent#enterprise applications#Azure AD roles#consent framework

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice