Courseiva

AZ-204 Practice Question: Connect to and consume Azure services and third-party services

A developer is creating an Azure Logic App that must call an external REST API. The API requires an OAuth 2.0 access token from Microsoft Entra ID. The Logic App will run on a schedule and must authenticate without user interaction. The developer has registered an app in Microsoft Entra ID and has a client secret. Which action should the developer take to configure the Logic App to authenticate to the API?

⚠ Common exam trap

The trap here is assuming that managed identity or basic authentication can be used, but the external API specifically requires an OAuth 2.0 token from Microsoft Entra ID, which the HTTP action can provide via client credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the HTTP action with Microsoft Entra ID OAuth authentication, providing the tenant ID, client ID, and client secret.

The HTTP action in Azure Logic Apps supports Microsoft Entra ID OAuth authentication. By specifying the tenant ID, client ID, and client secret, the Logic App can acquire an access token using the client credentials flow. This token is then included in the Authorization header when calling the external API. This approach works for scheduled runs without user interaction and meets the requirement of using OAuth 2.0 from Microsoft Entra ID.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the HTTP action with a managed identity and assign the identity the necessary permissions on the API.

    Why it's wrong here

    Managed identity can be used for Azure resources that support it, but the external API may not be configured to accept tokens from the Logic App's managed identity. The scenario specifies that the API requires an OAuth 2.0 token from Microsoft Entra ID, and the developer has a client secret for an app registration. Using managed identity would require the API to trust that identity, which is not stated. The correct approach is to use the app registration.

  • ✗

    Use the HTTP action with basic authentication, providing the client ID and client secret as username and password.

    Why it's wrong here

    Basic authentication sends credentials in base64-encoded format, which is not the same as OAuth 2.0. The external API requires an OAuth 2.0 access token, not basic authentication. Using basic auth would likely be rejected. The developer must use the Microsoft Entra ID OAuth option in the HTTP action to obtain a proper token.

  • ✗

    Use the HTTP action with a shared access signature (SAS) token in the header.

    Why it's wrong here

    A SAS token is used for Azure Storage, not for OAuth 2.0 authentication to an external API. The external API expects an OAuth 2.0 bearer token from Microsoft Entra ID, not a SAS token. Using a SAS token would result in authentication failure. The developer should configure Microsoft Entra ID OAuth in the HTTP action instead.

  • ✓

    Use the HTTP action with Microsoft Entra ID OAuth authentication, providing the tenant ID, client ID, and client secret.

    Why this is correct

    The HTTP action in Logic Apps supports Microsoft Entra ID OAuth authentication. By providing the tenant ID, client ID, and client secret, the Logic App can obtain an access token from Microsoft Entra ID and include it in the request to the external API. This method is suitable for scheduled runs without user interaction, as it uses the client credentials flow. The app registration must have the appropriate API permissions.

About these practice questions

This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.