AZ-204 Practice Question: Connect to and consume Azure services and third-party services
You are developing a .NET Core web API that will be hosted in Azure App Service. The API must authenticate users via Microsoft Entra ID (Azure AD) and call a downstream web API that is also protected by Microsoft Entra ID. You need to implement the On-Behalf-Of (OBO) flow. Which Microsoft identity platform library and method should you use to acquire a token for the downstream API?
⚠ Common exam trap
Many exam-takers confuse silent token acquisition with the on-behalf-of flow, which requires an explicit token exchange using the incoming token.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Microsoft.Identity.Client (MSAL) and call AcquireTokenOnBehalfOf with the incoming access token and the downstream API's scopes.
To implement the On-Behalf-Of flow, you use MSAL's AcquireTokenOnBehalfOf method. This method takes the incoming access token and requests a new token for the downstream API using the user's context. It is the standard way to handle delegated authentication in a middle-tier service. Other methods either do not perform the token exchange or are obsolete.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft.Identity.Web and call AddMicrosoftIdentityWebApiAuthentication to configure JWT bearer authentication, then call the downstream API with the same token.
Why it's wrong here
AddMicrosoftIdentityWebApiAuthentication configures the web API to validate incoming tokens, but it does not acquire a token for a downstream API. Using the same token is not possible because the audience and scopes are different. You must acquire a new token using the OBO flow.
- ✗
Use Microsoft.IdentityModel.Clients.ActiveDirectory (ADAL) and call AcquireTokenAsync with the client credential flow.
Why it's wrong here
ADAL is deprecated and does not support the OBO flow in the same way as MSAL. The client credential flow acquires a token for the application itself, not on behalf of the user. This would not provide user context to the downstream API. MSAL is the recommended library, and AcquireTokenOnBehalfOf is the correct method.
- ✓
Use Microsoft.Identity.Client (MSAL) and call AcquireTokenOnBehalfOf with the incoming access token and the downstream API's scopes.
Why this is correct
The OBO flow is implemented by calling AcquireTokenOnBehalfOf in MSAL. This method takes the incoming access token (from the client) and the scopes for the downstream API, and exchanges them for a new access token. This is the correct way to authenticate the web API to call another API on behalf of the user.
- ✗
Use Microsoft.Identity.Client (MSAL) and call AcquireTokenSilent with the downstream API's scopes.
Why it's wrong here
AcquireTokenSilent attempts to acquire a token from the cache without user interaction. However, in the OBO flow, the web API receives an access token from the client, and it must exchange that token for a new access token for the downstream API. AcquireTokenSilent alone cannot perform this exchange because it does not have a refresh token for the user; it would need to use the incoming token. The correct method is AcquireTokenOnBehalfOf.
Go deeper
Related to this question
Learn chapter
OAuth 2.0 Flows and MSAL Library
Key term
Microsoft Identity Platform
Microsoft Identity Platform is a unified authentication and authorization service that enables applications to sign in users and access resources using Microsoft Entra ID and modern protocols.
Key term
Azure AD B2C
Azure AD B2C is a cloud identity service that lets you customize and control how your customers sign up, sign in, and manage their profiles when using your applications.
About these practice questions
One of 883 original AZ-204 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.