You are viewing an application registration in Microsoft Entra ID. What can you conclude about this app?
This statement is correct as it accurately describes the application's configuration. The 'signInAudience' property being set to 'AzureADMyOrg' confirms it is a single-tenant application, restricted to users within the registering tenant. Furthermore, the 'AppRoles' collection is empty, indicating that no custom application-specific roles have been defined for granular access control within the application itself, while the 'Enabled' status is 'True'.
Why this answer
The application registration shows 'App roles' with a value of 0, which means no app roles are defined. The 'Supported account types' setting indicates 'Accounts in this organizational directory only', confirming it is a single-tenant application. The 'Enabled for users to sign-in?' toggle is set to 'Yes', so the app is enabled and can be used.
Exam trap
The trap here is that candidates often confuse a disabled app (where the 'Enabled for users to sign-in?' toggle is set to 'No') with an app that has no app roles defined, leading them to incorrectly select option A when the app is actually enabled but lacks roles.
How to eliminate wrong answers
Option A is wrong because the 'Enabled for users to sign-in?' toggle is set to 'Yes', meaning the app is enabled and can be used. Option C is wrong because the 'App roles' count is 0, indicating no custom roles are defined; custom roles would require at least one app role to be listed. Option D is wrong because the 'Supported account types' is set to 'Accounts in this organizational directory only', which explicitly restricts the app to a single tenant, not multi-tenant.