SC-100 Practice Question: Design security solutions for applications and data
Your organization is deploying a customer-facing web application in Azure. The application must authenticate users via Microsoft Entra ID and access Microsoft Graph to read user profiles. The security team requires that the application never has access to user passwords. Which authentication flow should you recommend?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OAuth 2.0 authorization code flow with PKCE
The correct option is D, OAuth 2.0 authorization code flow with PKCE, because it is the recommended flow for customer-facing web applications that authenticate users interactively via Microsoft Entra ID and call Microsoft Graph on their behalf. With PKCE, the client proves possession of a one-time code verifier, and the user authenticates directly against Entra ID, so the application never handles or sees user passwords. The resulting delegated access token also allows reading user profiles through Microsoft Graph with the appropriate scopes. Option A (implicit grant) is deprecated and exposes tokens in the browser URL fragment, while option B (device authorization flow) is intended for input-constrained devices and is not suited to a normal web app. Option C (client credentials grant) is app-only authentication with no user context, so it cannot authenticate users or read their profiles as required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OAuth 2.0 implicit grant flow
Why it's wrong here
Implicit grant flow is deprecated for web applications because the access token is returned directly in the URL fragment of the redirect URI. This exposes the token to browser history, referrer headers, and potentially malicious scripts, and the flow cannot safely issue a refresh token. Modern best practice, including Microsoft guidance, replaces it with the authorization code flow with PKCE.
- ✗
OAuth 2.0 device authorization flow
Why it's wrong here
Device authorization flow is intended for input-limited devices such as smart TVs, IoT devices, or CLI tools that cannot perform an interactive login. In a customer-facing web app, the user already has a fully capable browser, so requiring them to navigate to a separate URL and enter a code on another device is an unnecessary and poor experience. Additionally, the app must poll the token endpoint, adding complexity and latency that are not appropriate for a typical web application.
- ✗
OAuth 2.0 client credentials grant flow
Why it's wrong here
Client credentials grant flow authenticates the application itself to a resource server using its own secret, with no user identity or user consent involved. Because it cannot carry the signed-in user's profile or context, it is fundamentally unable to read user profiles on behalf of a specific user. This flow is reserved for server-to-server scenarios like background services or daemon apps, not for an interactive web application.
- ✓
OAuth 2.0 authorization code flow with PKCE
Why this is correct
Authorization code flow with PKCE is the recommended OAuth 2.0 flow for customer-facing web applications. The user authenticates and consents, and the app receives an authorization code rather than a token; this code is then exchanged for tokens using a PKCE verifier, ensuring that even if the code is intercepted it cannot be redeemed. The flow supports refresh tokens and never exposes the user's password to the app, making it secure for JavaScript and server-based web apps alike.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.