nerdexam
Microsoft

SC-300 · Question #292

Hotspot Question You have two Azure subscriptions named Sub1 and Sub2 that are linked to a Microsoft Entra tenant. The tenant contains three groups named Group1, Group2, and Group3. The…

The correct answer is User1 can request access to VM2 by using Permissions Management. = No; User2 can create an access request to Automation1 on behalf of User1. = Yes; User3 can approve access requests for VM2. = Yes. User3 can approve access requests for VM2 because Group3 is configured as an approver group in Permissions Management for Sub1 (where VM2 resides), and User3 is a member of Group3. User1 cannot request access to VM2 because User1 is not a member of any group that is configured…

Submitted by parkjh· Mar 6, 2026Manage identities and governance in Azure - specifically implementing and managing Microsoft Entra Permissions Management (formerly CloudKnox), including configuring requestors, approvers, and access request workflows across Azure subscriptions.

Question

Hotspot Question You have two Azure subscriptions named Sub1 and Sub2 that are linked to a Microsoft Entra tenant. The tenant contains three groups named Group1, Group2, and Group3. The subscriptions contain the resources shown in the following table. The tenant contains the users shown in the following table. You manage the subscriptions by using Microsoft Entra Permissions Management. Permissions Management is configured as shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

SC-300 question #292 exhibit 1
SC-300 question #292 exhibit 2

Answer Area

  • User1 can request access to VM2 by using Permissions Management.No
  • User2 can create an access request to Automation1 on behalf of User1.Yes
  • User3 can approve access requests for VM2.Yes

Explanation

User3 can approve access requests for VM2 because Group3 is configured as an approver group in Permissions Management for Sub1 (where VM2 resides), and User3 is a member of Group3. User1 cannot request access to VM2 because User1 is not a member of any group that is configured as a requestor in Permissions Management for Sub1. User2 cannot create an access request on behalf of User1 for Automation1 because the 'on-behalf-of' delegation feature requires specific permissions/role assignments in Permissions Management that User2 does not hold, and Automation1 is in Sub2 where User2 lacks this delegated requestor capability.

Topics

#Microsoft Entra Permissions Management#Azure RBAC#Just-in-Time Access#Identity Governance

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice