SC-300 · Question #191
Hotspot Question Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. The AD DS domain contains the organizational units (OUs)…
The correct answer is Location:: Azure AD; Role:: Global Administrator. A break-glass account is an emergency access account used to prevent being locked out of your Azure AD tenant in an outage. For this reason, it must be independent of the on-premises Active Directory Domain Services (AD DS) environment. Therefore, the account must be created…
Question
Exhibit
Answer Area
- Location:Azure ADAzure ADOU1OU2
- Role:Global AdministratorBilling AdministratorGlobal AdministratorOwnerPrivileged Role Administrator
How the community answered
(1 responses)- Azure AD|Owner100% (1)
Explanation
A break-glass account is an emergency access account used to prevent being locked out of your Azure AD tenant in an outage. For this reason, it must be independent of the on-premises Active Directory Domain Services (AD DS) environment. Therefore, the account must be created directly in Azure AD as a cloud-only account, not in OU1 (which syncs) or OU2 (which does not sync and would be on-premises only).
To ensure the break-glass account can perform any necessary recovery or administrative tasks during an emergency, it requires the highest level of administrative permissions. The Global Administrator role is the most privileged role in Azure AD, granting full control over all aspects of Azure AD and Microsoft 365 services, making it the appropriate choice for an emergency break-glass account.
Topics
Community Discussion
No community discussion yet for this question.
