GPEN Azure Apps and Attacks Practice Question
Network Topology
Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What security implication does this setting present for enterprise applications?
⚠ Common exam trap
Candidates often assume that setting 'appRoleAssignmentRequired' to false restricts access to administrators only, when in reality it opens access to all tenant users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Any user in the Microsoft Entra ID tenant can authenticate to the application and obtain access tokens without prior assignment.
The 'appRoleAssignmentRequired' property dictates whether users must be explicitly assigned to an enterprise application before they can successfully authenticate. When set to false, any user within the directory can acquire tokens for the application, expanding the attack surface and potential exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only users explicitly assigned via Microsoft Entra ID Enterprise Applications can authenticate and access the application.
Why it's wrong here
A false value means assignment is not enforced, so any user in the tenant can authenticate to the application without explicit assignment. The option inverts the logic: assignment enforcement is exactly what 'true' provides. Requiring explicit Enterprise Application assignment is tempting because it is the hardened configuration, but it is not what this setting produces.
- ✓
Any user in the Microsoft Entra ID tenant can authenticate to the application and obtain access tokens without prior assignment.
Why this is correct
Setting this property to false bypasses the user assignment requirement entirely. This default setting means every member of the directory is authorized to log in, which can be dangerous if the application contains sensitive internal functionality.
- ✗
The application is prohibited from utilizing OAuth 2.0 authorization code flows and must rely exclusively on client credentials.
Why it's wrong here
The setting controls assignment enforcement only; it does not restrict which OAuth 2.0 grant types an application may use. Authorization code and client credentials flows remain independently configurable. The option is tempting because both concern application access control, but the actual axis here is user assignment, not grant-type restriction.
- ✗
Global administrators must manually approve every single sign-in attempt generated by standard users in the tenant.
Why it's wrong here
'appRoleAssignmentRequired' governs whether user assignment is enforced before authentication; it does not insert a global administrator approval step into each sign-in. The tempting misconception is that tighter control equals admin gating, but no such per-sign-in approval mechanism exists in Microsoft Entra ID enterprise application configuration.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.