AZ-500 · Question #370
You have an Azure Active Directory (Azure AD) tenant that contains a user named User1. You need to ensure that User1 can create and manage administrative units. The solution must use the principle…
The correct answer is A. Privileged role administrator. To enable User1 to create and manage administrative units while adhering to the principle of least privilege, the Privileged role administrator role should be assigned.
Question
Options
- APrivileged role administrator
- BHelpdesk administrator
- CGlobal administrator
- DSecurity administrator
How the community answered
(21 responses)- A76% (16)
- B5% (1)
- C5% (1)
- D14% (3)
Why each option
To enable User1 to create and manage administrative units while adhering to the principle of least privilege, the Privileged role administrator role should be assigned.
The Privileged role administrator role allows a user to manage administrative units, including creating, deleting, and updating them. This role provides the necessary permissions specifically for administrative unit management without granting broader, unnecessary privileges, thereby adhering to the principle of least privilege.
The Helpdesk administrator role is primarily for resetting passwords and managing service requests, not for creating and managing administrative units.
The Global administrator role grants unrestricted access to all administrative features in Azure AD, violating the principle of least privilege for managing only administrative units.
The Security administrator role provides permissions to manage security-related features, such as security information and reports, but does not include the ability to manage administrative units.
Concept tested: Azure AD role-based access for administrative units
Source: https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#privileged-role-administrator
Topics
Community Discussion
No community discussion yet for this question.