SC-200 · Question #359
You have a Microsoft 365 E5 subscription that contains two groups named Group1 and Group2 and uses Microsoft Copilot for Security. You need to configure Copilot for Security role assignments to meet…
The correct answer is A. Assign the Security Operator role to Group1. E. Assign the Copilot Contributor role to Group2. Two actions are required to meet the requirements with least privilege after removing Everyone from Copilot Contributor. For Group2 (run prompts only): Assigning the Copilot Contributor role (E) is the least privileged option - it grants the ability to run prompts without…
Question
You have a Microsoft 365 E5 subscription that contains two groups named Group1 and Group2 and uses Microsoft Copilot for Security. You need to configure Copilot for Security role assignments to meet the following requirements:
- Ensure that members of Group1 can run prompts and respond to
Microsoft Defender XDR security incidents.
- Ensure that members of Group2 can run prompts.
- Follow the principle of least privilege.
You remove Everyone from the Copilot Contributor role. Which two actions should you perform next? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- AAssign the Security Operator role to Group1.
- BAssign the Copilot Owner role to Group2.
- CAssign the Copilot Owner role to Group1
- DAssign the Security Operator role to Group2.
- EAssign the Copilot Contributor role to Group2.
How the community answered
(29 responses)- A83% (24)
- B10% (3)
- C3% (1)
- D3% (1)
Explanation
Two actions are required to meet the requirements with least privilege after removing Everyone from Copilot Contributor. For Group2 (run prompts only): Assigning the Copilot Contributor role (E) is the least privileged option - it grants the ability to run prompts without elevated permissions. For Group1 (run prompts AND respond to Defender XDR incidents): Assigning the Security Operator role (A) is the correct least-privilege choice. The Security Operator role in Microsoft 365 grants permissions to manage and respond to security incidents in Microsoft Defender XDR, and it also maps to Copilot for Security access, enabling Group1 to run prompts. Assigning Copilot Owner to Group1 (C) would exceed the least-privilege requirement since it grants administrative Copilot capabilities beyond what Group1 needs. Assigning Security Operator to Group2 (D) would be excessive since Group2 only needs to run prompts.
Community Discussion
No community discussion yet for this question.