AZ-104 · Question #312
You have an Azure subscription that contains a user account named User1. You need to ensure that User1 can assign a policy to the tenant root management group. What should you do?
The correct answer is C. Assign the Global administrator role to User1, and then instruct User1 to configure access. No one is given default access to the root management group. Azure AD Global Administrators are the only users that can elevate themselves to gain access. Once they have access to the root management group, the global administrators can assign any Azure role to other users to…
Question
Options
- AAssign the Owner role for the Azure Subscription to User1, and then modify the default
- BAssign the Owner role for the Azure subscription to User1, and then instruct User1 to configure
- CAssign the Global administrator role to User1, and then instruct User1 to configure access
- DCreate a new management group and delegate User1 as the owner of the new management
How the community answered
(14 responses)- A7% (1)
- B21% (3)
- C64% (9)
- D7% (1)
Explanation
No one is given default access to the root management group. Azure AD Global Administrators are the only users that can elevate themselves to gain access. Once they have access to the root management group, the global administrators can assign any Azure role to other users to https://docs.microsoft.com/en-us/azure/governance/management-groups/overview#important- facts-about-the-root-management-group https://docs.microsoft.com/en-us/azure/governance/management-groups/overview
Community Discussion
No community discussion yet for this question.