nerdexam
Microsoft

MS-102 · Question #138

You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1. You enable Azure AD Identity Protection. You need to ensure that…

The correct answer is B. Security Administrator. Azure AD Identity Protection risky user reports require at minimum the Security Reader role to view, and Security Administrator to take remediation actions. In this question's option set, Security Reader is not available as a choice. Of the available roles, Security…

Submitted by sofia.br· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1. You enable Azure AD Identity Protection. You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege. To which role should you add User1?

Options

  • ACompliance Administrator
  • BSecurity Administrator
  • CService Administrator
  • DUser Administrator

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    81% (25)
  • C
    10% (3)
  • D
    3% (1)

Explanation

Azure AD Identity Protection risky user reports require at minimum the Security Reader role to view, and Security Administrator to take remediation actions. In this question's option set, Security Reader is not available as a choice. Of the available roles, Security Administrator provides access to Identity Protection (including risky users reports) and follows least privilege compared to Global Administrator. Compliance Administrator, Service Administrator, and User Administrator do not have access to Identity Protection risk reports.

Topics

#Azure AD Identity Protection#Role-based access control (RBAC)#Least privilege#Azure AD roles

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice