Q: 14
HOTSPOT You have an Azure Active Directory (Azure AD) tenant that has the default App registrations settings. The tenant contains the users shown in the following table. 
Your Answer
Discussion
CAN ASSIGN USERS TO APP1: ADMIN1 AND ADMIN3 ONLY
CAN REGISTER APP2 IN AZURE AD: ADMIN1, ADMIN2, ADMIN3, AND USER1
CAN REGISTER APP2 IN AZURE AD: ADMIN1, ADMIN2, ADMIN3, AND USER1
Yeah, saw a similar setup in practice-assigning users to App1 needs Application Admin or Cloud App Admin (so Admin1 and Admin3). Registering new apps is open by default, so all four can do App2 registration. Pretty sure that's right.
Assign App1: Admin1 and Admin3 only. Register App2: all four users (default lets everyone, unless setting changed). Nitpick, if user assignments were self-service then User1 could assign themself but that's not the case here.
That checks out, App assignments need Application Administrator or Cloud Application Administrator rights so only Admin1 and Admin3 qualify. For app registration, default lets any user do it unless restricted, so all four can register App2.
Not quite, it's not Admin2 for App1 assignments. Needs Application Admin or Cloud App Admin rights, so Admin1 and Admin3 only. Registering apps is open to everyone by default (all four). Easy to confuse the admin roles here.
CAN ASSIGN USERS TO APP1: Admin2 only
CAN REGISTER APP2 IN AZURE AD: Admin1, Admin3
I think Application Developer (Admin2) can assign users to App1 because they're listed as app owner, and only global/certain admin roles can register new apps. Not totally sure, open to corrections if I'm off.
CAN REGISTER APP2 IN AZURE AD: Admin1, Admin3
I think Application Developer (Admin2) can assign users to App1 because they're listed as app owner, and only global/certain admin roles can register new apps. Not totally sure, open to corrections if I'm off.
Be respectful. No spam.
