Add Custom Claims to Microsoft Entra ID Access Tokens
You are developing an ASP.NET Core app hosted in Azure App Service. The app requires custom claims to be returned from Microsoft Entra ID for user authorization. The claims must be removed when the app registration is removed. You need to include the custom claims in the user access token. What should you do?
Community Votes
100% of anonymous learners picked answer E. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The requirement that claims must be removed when the app registration is removed dictates using app roles over group membership claims, as app roles are tied to the application lifecycle.
Defining custom claims in Microsoft Entra ID tokens requires configuring the app manifest. This page establishes that adding roles to the appRoles attribute ensures claims are included in the token and automatically removed upon app registration deletion.
Choosing groupMembershipClaims (Option D) is common, but groups exist independently of the app registration and will not be deleted when the app is removed.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Adding roles to theappRoles attribute in the application manifest defines custom roles specific to the application. When a user or group is assigned to these roles, the claims are included in the access token. Because appRoles are defined within the app registration itself, they are automatically deleted when the app registration is removed, perfectly satisfying the question's lifecycle constraint.Why the Other Options Are Wrong
Option A requests the Microsoft Graph default scope, which grants access to Graph API but does not inject custom claims into the token. Option B merely specifies the authentication flow but does not configure custom claims. Option C suggests custom middleware, which adds unnecessary complexity and does not handle the lifecycle requirement of the claims. Option D usesgroupMembershipClaims, but Entra ID groups are tenant-level objects that persist independently of the app registration; deleting the app does not delete the groups or their associated claims.Community Comment Notes
Commenters correctly identified that the lifecycle constraint is the key differentiator, as AzDeveloper noted: "E not D because of this condition 'The claims must be removed when the app registration is removed.'" Another commenter pointed to the official documentation comparing app roles versus groups, reinforcing thatappRoles are tied to the application. Official Reference
Exam Strategy
Pay close attention to lifecycle constraints in authorization questions. If a claim or role must be deleted with the application, it must be defined within the app registration (like appRoles) rather than as a standalone directory object (like groups).