AZ-204 Implement Azure security Practice Question
You are developing a web application that authenticates users with the Microsoft identity platform. The application must call a downstream API on behalf of the signed-in user and must also be able to run a nightly maintenance job that calls the same API without any user present. You need to configure the app registration correctly. Which two actions should you perform? (Choose two.)
⚠ Common exam trap
The trap here is assuming one permission type can serve both a signed-in user and an unattended job, when delegated and application permissions are fundamentally different.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add delegated permissions for the downstream API scopes and acquire tokens using the authorization code flow with a user context.
The application has two distinct access patterns. Interactive calls on behalf of a user require delegated permissions and a user-context flow such as authorization code. The unattended nightly job requires application permissions granted with admin consent and the client credentials flow, which uses the app's identity rather than a user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a single delegated permission and use it for both the interactive user calls and the nightly job by caching the user's refresh token.
Why it's wrong here
Delegated permissions always require a user context, and a refresh token belongs to a specific user. A nightly job has no user, so reusing a stale refresh token is unreliable and violates the principle of least privilege. Background services must use application permissions with client credentials instead.
- ✗
Add a client secret to the app registration and use it as the sole credential for both interactive and background token requests.
Why it's wrong here
A client secret is a credential for the app itself and supports client credentials, but it cannot by itself produce delegated tokens for a signed-in user. Interactive calls need a user context and delegated scopes. Using one secret for both flows does not configure the required permission types, so the app registration would be incorrect.
- ✗
Enable implicit grant for ID tokens and access tokens in the app registration to support both interactive and background calls.
Why it's wrong here
Implicit grant is discouraged for web apps and is intended for browser-based single-page applications. It issues tokens directly from the authorization endpoint and does not support client credentials for background jobs. It cannot satisfy the unattended scenario, and using it for a confidential web app weakens security by exposing tokens in URLs.
- ✓
Add delegated permissions for the downstream API scopes and acquire tokens using the authorization code flow with a user context.
Why this is correct
On-behalf-of-user calls require delegated permissions and a user context. The authorization code flow obtains an authorization code after user sign-in, which is exchanged for an access token containing the delegated scopes. This enables the web app to call the downstream API as the signed-in user, satisfying the interactive portion of the requirement.
- ✓
Add application permissions for the downstream API and grant admin consent, then use the client credentials flow for the nightly job.
Why this is correct
A daemon job with no user requires application permissions, which are granted by an administrator and represent the app's own identity. The client credentials flow uses the app's credentials to obtain a token with those application roles. This allows the nightly maintenance job to call the API without a signed-in user, meeting the unattended requirement.
Go deeper
Related to this question
Learn chapter
Redis Cache Patterns: Cache-Aside, Session, Pub/Sub
Key term
Microsoft Identity Platform
Microsoft Identity Platform is a unified authentication and authorization service that enables applications to sign in users and access resources using Microsoft Entra ID and modern protocols.
Key term
Azure AD B2C
Azure AD B2C is a cloud identity service that lets you customize and control how your customers sign up, sign in, and manage their profiles when using your applications.
About these practice questions
This AZ-204 question is part of Courseiva's 883-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-204 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-204 exam.