Add Custom Claims to Microsoft Entra ID Access Tokens

Implement user authentication and authorization
Answer Correct answer: E — Add the roles to the appRoles attribute in the app manifest to ensure they are included in the token and deleted with the app registration.

You are developing an ASP.NET Core app hosted in Azure App Service. The app requires custom claims to be returned from Microsoft Entra ID for user authorization. The claims must be removed when the app registration is removed. You need to include the custom claims in the user access token. What should you do?

  1. Require the https://graph.microsoft.com/.default scope during authentication.
  2. Configure the app to use the OAuth 2.0 authorization code flow.
  3. Implement custom middleware to retrieve role information from Azure AD.
  4. Add the groups to the groupMembershipClaims attribute in the app manifest.
  5. Add the roles to the appRoles attribute in the app manifest. Correct Answer

Community Votes

E
100%

100% of anonymous learners picked answer E. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The requirement that claims must be removed when the app registration is removed dictates using app roles over group membership claims, as app roles are tied to the application lifecycle.

Defining custom claims in Microsoft Entra ID tokens requires configuring the app manifest. This page establishes that adding roles to the appRoles attribute ensures claims are included in the token and automatically removed upon app registration deletion.

Choosing groupMembershipClaims (Option D) is common, but groups exist independently of the app registration and will not be deleted when the app is removed.

Community Discussion (6 comments)

kygukyzo 👍 1 Selected: E
Correct
FeriAZ 👍 4 Selected: E
Azure Active Directory (Azure AD) supports adding custom roles to an application's manifest, which can then be assigned to users or groups. When a user is authenticated, these roles are included in the token as claims. This approach allows for fine-grained access control within your application based on these role assignments. Moreover, when the application registration is deleted, these roles and corresponding claims automatically cease to exist, fulfilling the requirement that the claims must be removed when the app registration is removed.
AzDeveloper 👍 3 Selected: E
E not D because of this condition "The claims must be removed when the app registration is removed."
AzDeveloper 👍 1
E not D because of this condition "The claims must be removed when the app registration is removed."
manopeydakon 👍 1
To include custom claims in the user access token from Microsoft Identity for user authorization, you should: E. Add the roles to the appRoles attribute in the app manifest. Explanation: In the Azure AD app manifest, you can define custom roles using the appRoles attribute. These roles can then be assigned to users, and the associated claims will be included in the user's token. Ensure that the appRoles attribute in the app manifest includes the necessary roles with associated claims, and assign these roles to users accordingly. This approach allows you to customize the claims included in the user's access token when they authenticate with Microsoft Identity.
Swekker 👍 3 Selected: E
AppRoles is the way to go. https://learn.microsoft.com/en-us/entra/identity-platform/howto-add-app-roles-in-apps#app-roles-vs-groups

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Adding roles to the appRoles attribute in the application manifest defines custom roles specific to the application. When a user or group is assigned to these roles, the claims are included in the access token. Because appRoles are defined within the app registration itself, they are automatically deleted when the app registration is removed, perfectly satisfying the question's lifecycle constraint.

Why the Other Options Are Wrong

Option A requests the Microsoft Graph default scope, which grants access to Graph API but does not inject custom claims into the token. Option B merely specifies the authentication flow but does not configure custom claims. Option C suggests custom middleware, which adds unnecessary complexity and does not handle the lifecycle requirement of the claims. Option D uses groupMembershipClaims, but Entra ID groups are tenant-level objects that persist independently of the app registration; deleting the app does not delete the groups or their associated claims.

Community Comment Notes

Commenters correctly identified that the lifecycle constraint is the key differentiator, as AzDeveloper noted: "E not D because of this condition 'The claims must be removed when the app registration is removed.'" Another commenter pointed to the official documentation comparing app roles versus groups, reinforcing that appRoles are tied to the application.

Official Reference

Exam Strategy

Pay close attention to lifecycle constraints in authorization questions. If a claim or role must be deleted with the application, it must be defined within the app registration (like appRoles) rather than as a standalone directory object (like groups).

Related Analysis

← Back to AZ-204 Study Guide