nerdexam
Microsoft

SC-300 · Question #452

You have a Microsoft Entra tenant. You need to ensure that users are prevented from consenting to high-privilege permission requests for enterprise applications. The solution must ensure that the…

The correct answer is C. User consent settings. To let users consent to low-risk permissions but block others in Microsoft Entra, use User Consent Settings in the Microsoft Entra admin center to select "Allow user consent for apps from verified publishers for selected permissions," then define those low-risk permissions…

Submitted by kim_seoul· Mar 6, 2026Implement access management for apps

Question

You have a Microsoft Entra tenant. You need to ensure that users are prevented from consenting to high-privilege permission requests for enterprise applications. The solution must ensure that the users can consent to low- risk permission requests. What should you modify first?

Options

  • AAdmin consent settings
  • BPermission classifications
  • CUser consent settings
  • DApp registrations

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    81% (26)
  • D
    9% (3)

Explanation

To let users consent to low-risk permissions but block others in Microsoft Entra, use User Consent Settings in the Microsoft Entra admin center to select "Allow user consent for apps from verified publishers for selected permissions," then define those low-risk permissions under Permission classifications, requiring admin approval for anything beyond that, especially high-risk or unverified app requests. This balances security by restricting risky requests (often flagged by risk-based step-up consent) while allowing productivity for trusted apps. https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent

Topics

#user consent settings#permission classifications#OAuth consent#enterprise applications

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice