AZ-104 · Question #724
Case Study 6 - ADatum Corporation Overview ADatum Corporation is consulting firm that has a main office in Montreal and branch offices in Seattle and New York. Existing Environment Azure Environment…
The correct interaction is to select 'No' for all three statements because assigning Microsoft Entra custom security attributes requires the specific 'Attribute Assignment Administrator' role, which is not granted by default to general administrative accounts and is not…
Question
Exhibit
Answer Area
- Admin1 can assign Attribute1 to Group1.
- Admin2 can assign Attribute1 to User1.
- Admin3 can assign Attribute1 to Group2.
Explanation
The correct interaction is to select 'No' for all three statements because assigning Microsoft Entra custom security attributes requires the specific 'Attribute Assignment Administrator' role, which is not granted by default to general administrative accounts and is not indicated in the case study for Admin1, Admin2, or Admin3.
Approach. For each of the three statements presented, the correct interaction is to select the 'No' radio button.
Common mistakes.
- common_mistake. A common mistake is assuming that any user named 'AdminX' or holding a general administrative role (like Global Administrator) automatically possesses all necessary permissions within Microsoft Entra ID, including the ability to manage custom security attributes. This is incorrect; custom security attributes adhere to the principle of least privilege and require specific, dedicated roles ('Attribute Assignment Administrator' for assigning, and 'Attribute Definition Administrator' for defining) that are not part of broader administrative roles. Another mistake could be confusing the role needed to define (create/manage) custom attributes with the role needed to assign them, or simply not being aware of these specific required roles at all.
Concept tested. The core technical concept being tested is the understanding of Microsoft Entra Custom Security Attributes and the specific Role-Based Access Control (RBAC) permissions, specifically the 'Attribute Assignment Administrator' role, required to assign these attributes to user and group objects in Microsoft Entra ID. It assesses knowledge of granular permissions and the principle of least privilege in Azure AD.
Topics
Community Discussion
No community discussion yet for this question.
