SC-300 - Plan and Implement Workload Identities (25% of the exam) - Section 3.3

Manage enterprise application access, user and admin consent, and app collections.

Assign users and groups to enterprise applications, map app roles, and control what users can consent to via user consent settings. Configure the admin consent workflow so requests for high-privilege permissions are reviewed before grant, and organise apps into application collections for the My Apps portal.

user and group assignment to appsapp role assignmentuser consent settingsadmin consent workflowapplication collections

Practice question for this objective

Free samplePlan and Implement Workload Identitiesmedium

A tenant has disabled user consent and is enabling the admin consent workflow so employees can request access to applications they cannot consent to. The security team insists that the people who approve these consent requests must be able to actually grant tenant-wide consent on behalf of the organisation. Which role must the designated reviewers hold for their approvals to take effect?

  • AReports Reader, so reviewers can read the consent request telemetry before approving each application
  • BA role able to grant tenant-wide consent, such as Cloud Application Administrator, Application Administrator, or Global Administrator Correct
  • CGroups Administrator, so reviewers can assign the approved application to the requesting user's groups
  • DHelpdesk Administrator, since approving consent requests is treated as a routine user support task
Recognise that admin consent workflow reviewers must hold a role able to grant tenant-wide consent, such as Cloud Application Administrator or Application Administrator. Approving an admin consent request grants permissions on behalf of the whole tenant, an action limited to roles with consent rights. Designated reviewers therefore need Cloud Application Administrator, Application Administrator, or Global Administrator; lesser roles can read or support but cannot complete the consent grant.

Why A is wrong: Reports Reader only grants read access to reports and sign-in data; it confers no ability to grant consent, so a reviewer with this role could not action a request.

Why B is correct: Granting consent on behalf of the organisation requires permission to consent to applications, which Cloud Application Administrator, Application Administrator, and Global Administrator provide, so designated reviewers must hold one of these.

Why C is wrong: Groups Administrator manages group membership and has no rights over application consent, so a reviewer with only this role could not grant the requested permissions.

Why D is wrong: Helpdesk Administrator covers password resets and limited user support and cannot grant application consent, so approvals from a reviewer holding only this role would fail.

See more SC-300 practice questions, answers explained.

Exam traps in Plan and Implement Workload Identities

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-300 bank for this domain.

  • On the enterprise application's Properties page, set Assignment required to No so all users gain access without consent

    Why it is wrong: Assignment required controls who may access the application, not whether permissions are consented; turning it off does not approve the requested Graph permissions for the tenant.

  • A Conditional Access policy that grants access to the application once the user satisfies a compliant-device control, which also approves the requested Graph permissions.

    Why it is wrong: Conditional Access governs session conditions such as device or location but never grants or approves application API permissions, so it cannot unblock a consent-driven failure.

  • On the app registration's App roles page, edit the Approver role definition and add Mei to its allowed member types

    Why it is wrong: The App roles page defines which roles the application exposes and their allowed member types; it declares roles but does not assign a named user to one, so it cannot grant Mei the role.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.