MicrosoftMicrosoft
SC-300 · Question #451
SC-300 Question #451: Real Exam Question with Answer & Explanation
The correct answer is D: From the Microsoft Entra admin center, configure the Admin consent settings.. From the Microsoft Entra admin center, configure the Admin consent settings. From the Microsoft 365 Defender portal, configure an app connector. From the Microsoft 365 Defender portal, create a Cloud Discovery anomaly detection policy. From the Microsoft Defender portal, create a
Submitted by jakub_pl· Mar 6, 2026
Question
You have a Microsoft Entra tenant. You discover that a large number of new apps were added to the tenant. You need to implement an approval process for new enterprise applications. What should you do?
Options
- AFrom the Microsoft Defender portal, configure an app connector.
- BFrom the Microsoft Entra admin center, configure an access review.
- CFrom the Microsoft Defender portal, create an app detection policy.
- DFrom the Microsoft Entra admin center, configure the Admin consent settings.
Explanation
- From the Microsoft Entra admin center, configure the Admin consent settings. * From the Microsoft 365 Defender portal, configure an app connector. * From the Microsoft 365 Defender portal, create a Cloud Discovery anomaly detection policy. * From the Microsoft Defender portal, create an app detection policy. * From the Microsoft Entra admin center, configure an access review. Configure the admin consent workflow The admin consent workflow gives admins a secure way to grant access to applications that require admin approval. When a user tries to access an application but is unable to provide consent, they can send a request for admin approval. The request is sent via email to admins who have been designated as reviewers. A reviewer takes action on the request, and the user is notified of the action. Enable the admin consent workflow To enable the admin consent workflow and choose reviewers: Sign in to the Microsoft Entra admin center as as a Global Administrator. Browse to Identity > Applications > Enterprise applications > Consent and permissions > Admin consent settings. Under Admin consent requests, select Yes for Users can request admin consent to apps they are unable to consent to . Note: Access and consent You can manage user consent settings to choose whether users can allow an application or service to access user profiles and organizational data. When applications are granted access, users can sign in to applications integrated with Azure AD, and the application can access your organization's data to d’liver rich data-driven experiences. In situations where users are unable to consent to the permissions an application is requesting, consider configuring the admin consent workflow. The workflow allows users to provide a justification and request an administrator's review an approval of an application. https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/configure-admin-consent-
Community Discussion
No community discussion yet for this question.