SC-300 · Question #304
Hotspot Question You have a Microsoft 365 E5 subscription. You need to configure app consent for the subscription. The solution must meet the following requirements: - Disable user consent to apps…
The correct answer is Disable user consent to apps:: Microsoft 365 admin center; Configure admin consent workflow for apps:: Microsoft Entra admin center. Hotspot Explanation: App Consent Configuration in Microsoft 365 E5 --- Dropdown 1: Disable user consent to apps Correct Answer: Microsoft 365 admin center Why it's correct: In the Microsoft 365 admin center, under Settings -> Org settings -> Services -> User consent to apps…
Question
Hotspot Question You have a Microsoft 365 E5 subscription. You need to configure app consent for the subscription. The solution must meet the following requirements:
- Disable user consent to apps.
- Configure admin consent workflow for apps.
Which portal should you use for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:
Answer Area
- Disable user consent to apps:Microsoft 365 admin centerMicrosoft 365 admin centerMicrosoft 365 Apps admin centerMicrosoft 365 Defender portalMicrosoft Purview compliance portal
- Configure admin consent workflow for apps:Microsoft Entra admin centerMicrosoft Entra admin centerMicrosoft 365 admin centerMicrosoft 365 Defender portalMicrosoft Purview compliance portal
Explanation
Hotspot Explanation: App Consent Configuration in Microsoft 365 E5
Dropdown 1: Disable user consent to apps
Correct Answer: Microsoft 365 admin center
Why it's correct: In the Microsoft 365 admin center, under Settings -> Org settings -> Services -> User consent to apps, administrators can toggle off the ability for users to consent to third-party apps accessing organizational data. This is the simplified administrative surface for this org-wide policy.
Why the others are wrong:
- Microsoft 365 Apps admin center - Manages Office app deployment, updates, and policies (e.g., which Office apps are deployed). It has no role in OAuth app consent.
- Microsoft 365 Defender portal - Focused on security threat detection, incidents, and XDR. Not used for identity or consent policy configuration.
- Microsoft Purview compliance portal - Handles data governance, DLP, retention, and compliance. Not related to app consent settings.
Dropdown 2: Configure admin consent workflow for apps
Correct Answer: Microsoft Entra admin center
Why it's correct: The admin consent workflow is an Azure AD / Microsoft Entra ID feature. It is configured at: Microsoft Entra admin center -> Enterprise applications -> Consent and permissions -> Admin consent settings
This workflow allows users to request admin approval for apps they cannot consent to themselves, rather than being silently blocked. Reviewers (admins) receive and approve/deny these requests.
Why the others are wrong:
- Microsoft 365 admin center - Can disable user consent (Dropdown 1), but does not expose the granular admin consent workflow configuration.
- Microsoft 365 Defender portal - Security/XDR portal; no identity consent workflow features.
- Microsoft Purview compliance portal - Compliance and data governance; unrelated to OAuth consent workflows.
Core Technical Concept
This question tests knowledge of the separation of concerns between portals:
- Microsoft 365 admin center = simplified org-wide toggles for Microsoft 365 services
- Microsoft Entra admin center = granular identity, access, and application consent policies (the authoritative source for Azure AD app governance)
The admin consent workflow is purely an Entra/Azure AD identity feature, which is why it lives exclusively in the Entra admin center, even though both portals touch app consent at different levels.
Topics
Community Discussion
No community discussion yet for this question.