Courseiva

AZ-204 Practice Question: Connect to and consume Azure services and third-party services

Which THREE components are required to implement a secure authentication flow for a single-page application (SPA) using Microsoft Entra ID to call Microsoft Graph? (Choose three.)

⚠ Common exam trap

It's easy for candidates to confuse the requirements for confidential clients (client secret or certificate) with those for public clients like SPAs, leading them to incorrectly select client secret or client certificate instead of recognizing that SPAs rely on PKCE and do not use client secrets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorization endpoint

Option B (Authorization endpoint) is required because the SPA must redirect the user to the Microsoft Entra ID authorization endpoint (https://login.microsoftonline.com/{tenant}/oauth2/v2.0/authorize) to initiate the OAuth 2.0 authorization code flow with PKCE and obtain user consent. Option C (Client ID / Application ID) is required because every app registration in Microsoft Entra ID is uniquely identified by its Application (client) ID, which the SPA sends in the authorization and token requests to identify itself. Option E (Token endpoint) is required because the SPA must exchange the authorization code (with the PKCE code_verifier) at the token endpoint (https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token) to receive the access token used to call Microsoft Graph. Option A (Client certificate) is not needed, as certificates are used for confidential client or daemon/service authentication, not for browser-based SPAs. Option D (Client secret) is not needed and is in fact prohibited for SPAs, since public clients cannot securely store secrets; PKCE replaces the secret in this flow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Client certificate

    Why it's wrong here

    A client certificate is a credential used by confidential client applications to authenticate themselves to the authorization server, typically in scenarios where the client can securely store a private key. For public clients, such as Single-Page Applications (SPAs) or mobile apps, securely storing a client certificate is not feasible. Therefore, it is not a required component for a secure authentication flow involving public clients, which rely on other mechanisms like PKCE for enhanced security.

  • ✓

    Authorization endpoint

    Why this is correct

    The authorization endpoint is a critical component where the user interacts with the identity provider to authenticate and grant consent for the client application to access protected resources. It initiates the authorization flow, typically by redirecting the user's browser, and upon successful authentication and consent, it returns an authorization code to the client application's registered redirect URI. This step is fundamental for obtaining the initial authorization code that will later be exchanged for tokens.

  • ✓

    Client ID (Application ID)

    Why this is correct

    The Client ID (also known as Application ID) is a globally unique identifier assigned to an application when it is registered with an identity provider, such as Microsoft Entra ID. This ID is essential for the authorization server to recognize which specific application is requesting authentication and authorization. It ensures that the correct permissions, redirect URIs, and other application-specific configurations are applied during the authentication process.

  • ✗

    Client secret

    Why it's wrong here

    A client secret is a confidential credential used by confidential client applications (e.g., web applications with a backend, daemon services) to authenticate themselves directly to the authorization server. Public clients, such as Single-Page Applications (SPAs) or native mobile applications, cannot securely store a client secret, as it would be exposed to end-users. Therefore, using a client secret is inappropriate and insecure for these types of applications in a secure authentication flow.

  • ✓

    Token endpoint

    Why this is correct

    The token endpoint is where the client application exchanges the authorization code, obtained from the authorization endpoint, for access tokens, refresh tokens, and ID tokens. This exchange occurs directly between the client application's backend (or a secure client-side component for public clients using PKCE) and the authorization server over a secure, direct channel. It is a crucial step for acquiring the necessary tokens to access protected APIs and maintain user sessions.

About these practice questions

This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.