nerdexam
Microsoft

SC-200 · Question #356

You have a Microsoft 365 E5 subscription that uses Microsoft Copilot for Security. Copilot for Security has the default settings configured. You need to ensure that a user named User can use Copilot…

The correct answer is A. Copilot owner. Microsoft Copilot for Security defines two built-in Copilot roles: Copilot Owner and Copilot Contributor. Copilot Contributor can run prompts and create promptbooks, but cannot upload files, view the usage dashboard, or share promptbooks with all users. Copilot Owner provides…

Submitted by andreas_gr· Apr 18, 2026

Question

You have a Microsoft 365 E5 subscription that uses Microsoft Copilot for Security. Copilot for Security has the default settings configured. You need to ensure that a user named User can use Copilot for Security to perform the following tasks:

  • Upload files.
  • View the usage dashboard.
  • Share promptbooks with all users.

The solution must follow the principle of least privilege Which role should you assign to User?

Options

  • ACopilot owner
  • BCloud Application Administrator
  • CSecurity Administrator
  • DCopilot Contributor

How the community answered

(31 responses)
  • A
    74% (23)
  • B
    3% (1)
  • C
    16% (5)
  • D
    6% (2)

Explanation

Microsoft Copilot for Security defines two built-in Copilot roles: Copilot Owner and Copilot Contributor. Copilot Contributor can run prompts and create promptbooks, but cannot upload files, view the usage dashboard, or share promptbooks with all users. Copilot Owner provides all Contributor capabilities plus the ability to upload files, access the usage dashboard, share promptbooks with all users, and manage role assignments. Since the requirements include all three tasks - uploading files, viewing the usage dashboard, and sharing promptbooks with all users - only the Copilot Owner role satisfies them. Security Administrator and Cloud Application Administrator are Azure AD roles that do not grant these Copilot-specific capabilities. Copilot Owner is therefore the least privileged role that meets all requirements.

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice