nerdexam
Microsoft

SC-300 · Question #111

You are looking to improve your organizations security posture after hearing about breaches and hacks of other organizations on the news. You have been looking into Azure Identity Protection and you…

The correct answer is C. Security Administrator. Security Administrator (Option C) is the appropriate role because it grants full read and write access to Azure Identity Protection features - including configuring policies, reviewing risky users/sign-ins, and managing alerts - without including password reset capabilities…

Submitted by sofia.br· Mar 6, 2026Implement authentication and access management

Question

You are looking to improve your organizations security posture after hearing about breaches and hacks of other organizations on the news. You have been looking into Azure Identity Protection and you are commissioning a team to begin implementing this service. This team will need full access to Identity Protection but would not need to reset passwords. You should follow the principle of least privilege. What role should you grant this new team?

Options

  • ASecurity Operator
  • BGlobal Administrator
  • CSecurity Administrator
  • DHelpDesk Administrator

How the community answered

(41 responses)
  • A
    7% (3)
  • B
    12% (5)
  • C
    78% (32)
  • D
    2% (1)

Explanation

Security Administrator (Option C) is the appropriate role because it grants full read and write access to Azure Identity Protection features - including configuring policies, reviewing risky users/sign-ins, and managing alerts - without including password reset capabilities, perfectly aligning with the principle of least privilege.

Why the other options are wrong:

  • Security Operator (A) has limited permissions in Identity Protection, primarily read-only access, and cannot fully manage or configure the service.
  • Global Administrator (B) does have full access to Identity Protection (and can reset passwords), but granting this role violates least privilege since it provides far more permissions than needed across the entire Azure tenant.
  • HelpDesk Administrator (D) is focused on password resets and basic user support tasks - it does not provide the necessary access to Identity Protection features.

Memory Tip: Think of it this way - "Security Admin secures, HelpDesk resets." Whenever a question asks about full security feature management without password reset rights, Security Administrator is your go-to. If password resets are required alongside security tasks, that's a clue to consider a higher-privileged role - but only if least privilege isn't a concern.

Topics

#Azure Identity Protection#Azure AD Built-in Roles#Principle of Least Privilege#Access Control

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice