SC-300 - Plan and Implement Workload Identities - Section 3.3

Manage enterprise application access, user and admin consent, and app collections.

Assign users and groups to enterprise applications, map app roles, and control what users can consent to via user consent settings. Configure the admin consent workflow so requests for high-privilege permissions are reviewed before grant, and organise apps into application collections for the My Apps portal.

user and group assignment to appsapp role assignmentuser consent settingsadmin consent workflowapplication collections

Practice question for this objective

Free samplePlan and Implement Workload Identitiesmedium

A tenant has disabled user consent and is enabling the admin consent workflow so employees can request access to applications they cannot consent to. The security team insists that the people who approve these consent requests must be able to actually grant tenant-wide consent on behalf of the organisation. Which role must the designated reviewers hold for their approvals to take effect?

  • AReports Reader, so reviewers can read the consent request telemetry before approving each application
  • BA role able to grant tenant-wide consent, such as Cloud Application Administrator, Application Administrator, or Global Administrator Correct
  • CGroups Administrator, so reviewers can assign the approved application to the requesting user's groups
  • DHelpdesk Administrator, since approving consent requests is treated as a routine user support task
Recognise that admin consent workflow reviewers must hold a role able to grant tenant-wide consent, such as Cloud Application Administrator or Application Administrator. Approving an admin consent request grants permissions on behalf of the whole tenant, an action limited to roles with consent rights. Designated reviewers therefore need Cloud Application Administrator, Application Administrator, or Global Administrator; lesser roles can read or support but cannot complete the consent grant.

Why A is wrong: Reports Reader only grants read access to reports and sign-in data; it confers no ability to grant consent, so a reviewer with this role could not action a request.

Why B is correct: Granting consent on behalf of the organisation requires permission to consent to applications, which Cloud Application Administrator, Application Administrator, and Global Administrator provide, so designated reviewers must hold one of these.

Why C is wrong: Groups Administrator manages group membership and has no rights over application consent, so a reviewer with only this role could not grant the requested permissions.

Why D is wrong: Helpdesk Administrator covers password resets and limited user support and cannot grant application consent, so approvals from a reviewer holding only this role would fail.

See more SC-300 practice questions, answers explained.

More in this domain

Back to all Plan and Implement Workload Identities objectives, or the SC-300 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.