Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Entra ID and has a custom role that grants 'microsoft.directory/applications/credentials/update' permission. A security audit reveals that a user assigned this role has modified credentials for an application. You need to prevent such actions while allowing other application updates. What should you do?

⚠ Common exam trap

Candidates often think removing the user from the custom role and assigning a different role (Option C) is the simplest fix, but that would likely revoke all application update permissions, failing the requirement to allow other updates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a custom role that excludes the 'microsoft.directory/applications/credentials/update' permission and assign it to the user.

The custom role currently includes the 'microsoft.directory/applications/credentials/update' permission, which allows modifying application credentials. To prevent credential updates while still permitting other application updates, you must create a new custom role that explicitly excludes this permission and assign it to the user. This approach preserves granular control without granting unnecessary privileges, unlike built-in roles that would either over-scope or under-scope permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign the user the built-in Application Administrator role instead.

    Why it's wrong here

    Assigning the built-in Application Administrator role would be ineffective because it explicitly includes the 'microsoft.directory/applications/credentials/update' permission, so the user would still be able to update application secrets. Additionally, built-in roles grant a broader set of permissions than needed, violating the principle of least privilege. This approach does not address the requirement to block only credential updates.

  • ✗

    Enable multi-factor authentication for the user.

    Why it's wrong here

    Enabling multi-factor authentication (MFA) for the user does not alter the user's authorization; MFA only adds an additional authentication step at sign-in. Once the user passes MFA, the custom role still grants them the permission to update application credentials, so they can still perform the action. MFA is an identity verification control, not a permission-control mechanism.

  • ✗

    Remove the user from the custom role and assign them another role with fewer permissions.

    Why it's wrong here

    Removing the user from the custom role and assigning a differently scoped role would revoke the user's ability to perform all application update tasks, not just credential updates. The user likely still needs other permissions from the custom role, such as updating application metadata or ownership, so a broadly fewer permission role could disrupt legitimate operations. The correct fix is to retain the necessary permissions and specifically omit the credential update permission.

  • ✓

    Create a custom role that excludes the 'microsoft.directory/applications/credentials/update' permission and assign it to the user.

    Why this is correct

    Creating a custom role that omits the 'microsoft.directory/applications/credentials/update' permission ensures the user cannot change application secrets, certificates, or passwords, while still allowing other application management actions. Custom roles in Microsoft Entra ID allow you to compose a permission set from the available permissions, enabling you to exclude sensitive operations. Assigning this custom role to the user satisfies the requirement to prevent credential updates without over-restricting other updates.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.