nerdexam
Microsoft

MS-102 · Question #333

You have a Microsoft 365 subscription that contains a Microsoft Entra tenant named contoso.com. The tenant includes a user named User1. You enable Microsoft Entra ID Protection. You need to ensure…

The correct answer is A. Security Reader. The Security Reader role grants read-only access to security information across Microsoft 365 security services, including the ability to view risky users and risk reports in Microsoft Entra ID Protection. This satisfies the requirement using the principle of least privilege…

Submitted by klara.se· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

You have a Microsoft 365 subscription that contains a Microsoft Entra tenant named contoso.com. The tenant includes a user named User1. You enable Microsoft Entra ID Protection. You need to ensure that User1 can review the list in Microsoft Entra ID Protection of users flagged for risk. The solution must use the principle of least privilege. To which role should you add User1?

Options

  • ASecurity Reader
  • BReports Reader
  • CCompliance Administrator
  • DOwner

How the community answered

(49 responses)
  • A
    92% (45)
  • B
    2% (1)
  • C
    2% (1)
  • D
    4% (2)

Explanation

The Security Reader role grants read-only access to security information across Microsoft 365 security services, including the ability to view risky users and risk reports in Microsoft Entra ID Protection. This satisfies the requirement using the principle of least privilege. The Reports Reader role (B) provides access to usage reports but not Identity Protection risk data. Compliance Administrator (C) focuses on compliance and data governance, not identity risk. Owner (D) is overly permissive and violates least privilege.

Topics

#Microsoft Entra ID Protection#Role-Based Access Control (RBAC)#Least Privilege#Security Reader

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice