Soru

Zorluk: KolayApp Registrations and Service Principals

An organization is developing a multi-tenant web application. You register the application in your home Microsoft Entra ID tenant. Which resource is automatically created in a customer's tenant when their administrator consents to allow your application to access their resources?

  1. A service principalCevap
  2. B
    An application registration
  3. C
    A system-assigned managed identity
  4. D
    A user-assigned managed identity

Cevap

A service principal
A service principal is the local representation of the application in a specific Microsoft Entra ID tenant. When an administrator consents to a multi-tenant application, a service principal is created in that tenant to hold the permissions and access configuration.

Adım Adım Çözüm

1
Differentiate between the global application object and local tenant identities.
The application registration acts as the global template created in the home tenant, while the service principal acts as the local instance.
Understanding this distinction helps clarify which object is created in the target tenant to hold the local consent and permissions.
2
Analyze the consent workflow for multi-tenant applications.
When a customer administrator grants consent, Microsoft Entra ID creates a local instance of the application to authorize access to resources within that specific tenant.
This shows how the local representation is instantiated to manage permissions.
3
Select the correct Azure identity resource that represents this local instance.
The local instance created in the customer tenant is a service principal.
Service principals are the security identities used to define access policies and permissions for applications within specific Microsoft Entra ID tenants.

Anahtar Kavram

The relationship between Application Registrations and Service Principals in Microsoft Entra ID.
Tahmini Süre:45s
Bu soruyu puanla