nerdexam
Microsoft

SC-300 · Question #191

Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. The AD DS domain contains the organizational units (OUs)…

The correct answer is Location:: Azure AD; Role:: Global Administrator. A break-glass account is an emergency access account used to prevent being locked out of your Azure AD tenant in an outage. For this reason, it must be independent of the on-premises Active Directory Domain Services (AD DS) environment. Therefore, the account must be created…

Submitted by viktor_hu· Mar 6, 2026Implement and manage user identities

Question

Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. The AD DS domain contains the organizational units (OUs) shown in the following table. You need to create a break-glass account named BreakGlass. Where should you create BreakGlass, and which role should you assign to BreakGlass? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibit

SC-300 question #191 exhibit

Answer Area

  • Location:Azure AD
    Azure ADOU1OU2
  • Role:Global Administrator
    Billing AdministratorGlobal AdministratorOwnerPrivileged Role Administrator

How the community answered

(1 responses)
  • Azure AD|Owner
    100% (1)

Explanation

A break-glass account is an emergency access account used to prevent being locked out of your Azure AD tenant in an outage. For this reason, it must be independent of the on-premises Active Directory Domain Services (AD DS) environment. Therefore, the account must be created directly in Azure AD as a cloud-only account, not in OU1 (which syncs) or OU2 (which does not sync and would be on-premises only).

To ensure the break-glass account can perform any necessary recovery or administrative tasks during an emergency, it requires the highest level of administrative permissions. The Global Administrator role is the most privileged role in Azure AD, granting full control over all aspects of Azure AD and Microsoft 365 services, making it the appropriate choice for an emergency break-glass account.

Topics

#break-glass accounts#Azure AD#role assignment#emergency access

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice