Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization uses Microsoft Entra ID and has an application that requires the 'User.Read.All' permission. You need to grant this permission to the application but ensure that only an administrator can consent, not users. What should you do?

⚠ Common exam trap

Many exam-takers confuse blocking user consent (Option D) with granting admin consent, thinking that blocking users automatically grants the permission, but blocking only prevents consent without actually authorizing the application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant admin consent for the application from the Enterprise applications blade.

Granting admin consent from the Enterprise applications blade explicitly authorizes the application to access the 'User.Read.All' permission without requiring individual user consent. This is the only way to satisfy the requirement that only an administrator can consent, as admin consent bypasses user consent policies entirely and applies tenant-wide.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant admin consent for the application from the Enterprise applications blade.

    Why this is correct

    Granting admin consent from the Enterprise applications blade (by selecting the application, then clicking 'Grant admin consent' under Security/Permissions) authorizes the app's requested permissions for every user in the tenant. This is the only effective solution because the application likely requests high-risk permissions, such as Graph API application permissions, that must be consented to by a tenant administrator, not an end user. Once admin consent is granted, the application's status changes to 'Granted' and users can access it without being prompted for consent.

  • ✗

    Enable user consent for this application in the enterprise application settings.

    Why it's wrong here

    There is no per-application 'enable user consent' setting in the Enterprise applications blade; user consent is controlled tenant-wide through the 'User consent settings' in the Entra admin center, not per-app. Moreover, user consent cannot be enabled for high-risk permissions that require admin consent, so this approach would still fail to authorize the application. Only an explicit admin grant can satisfy the application's permission requirements.

  • ✗

    Configure the user consent settings to allow user consent for low-risk permissions.

    Why it's wrong here

    Configuring user consent settings to allow user consent for low-risk permissions only affects permissions that Microsoft has classified as not requiring admin consent; it does not grant any consent to a specific application. The application in question is explicitly requesting high-risk permissions, so this setting would not permit users to consent and no access would be granted. A separate, explicit admin consent action is needed to fulfill the application's permission requirements.

  • ✗

    Set the 'Consent and permissions' settings to block user consent.

    Why it's wrong here

    Blocking user consent in the 'Consent and permissions' settings prevents end users from granting any application permissions, but it does not itself grant admin consent for the application. Doing so would actually make the app non-functional for users until admin consent is granted via the Enterprise applications blade. This setting is a security control, not a consent authorization, and it has no effect on the app's ability to acquire the required high-risk permissions.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.