nerdexam
Microsoft

AZ-500 · Question #370

You have an Azure Active Directory (Azure AD) tenant that contains a user named User1. You need to ensure that User1 can create and manage administrative units. The solution must use the principle…

The correct answer is A. Privileged role administrator. To enable User1 to create and manage administrative units while adhering to the principle of least privilege, the Privileged role administrator role should be assigned.

Submitted by yousef_jo· Mar 6, 2026Secure identity and access

Question

You have an Azure Active Directory (Azure AD) tenant that contains a user named User1. You need to ensure that User1 can create and manage administrative units. The solution must use the principle of least privilege. Which role should you assign to User1?

Options

  • APrivileged role administrator
  • BHelpdesk administrator
  • CGlobal administrator
  • DSecurity administrator

How the community answered

(21 responses)
  • A
    76% (16)
  • B
    5% (1)
  • C
    5% (1)
  • D
    14% (3)

Why each option

To enable User1 to create and manage administrative units while adhering to the principle of least privilege, the Privileged role administrator role should be assigned.

APrivileged role administratorCorrect

The Privileged role administrator role allows a user to manage administrative units, including creating, deleting, and updating them. This role provides the necessary permissions specifically for administrative unit management without granting broader, unnecessary privileges, thereby adhering to the principle of least privilege.

BHelpdesk administrator

The Helpdesk administrator role is primarily for resetting passwords and managing service requests, not for creating and managing administrative units.

CGlobal administrator

The Global administrator role grants unrestricted access to all administrative features in Azure AD, violating the principle of least privilege for managing only administrative units.

DSecurity administrator

The Security administrator role provides permissions to manage security-related features, such as security information and reports, but does not include the ability to manage administrative units.

Concept tested: Azure AD role-based access for administrative units

Source: https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#privileged-role-administrator

Topics

#administrative units#privileged role administrator#least privilege#Azure AD roles

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice