nerdexam
Microsoft

SC-300 · Question #389

Hotspot Question You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains the identities shown in the following table. The tenant is onboarded to Permissions…

The correct answer is Accounts assigned to highly privileged roles: Group1; Service principals with privileged role assignments: App1. This question tests knowledge of Microsoft Entra Permissions Management Insights, specifically which identity types appear under 'Accounts assigned to highly privileged roles' versus 'Service principals with privileged role assignments'.

Submitted by krish.m· Mar 6, 2026Plan and implement identity governance

Question

Hotspot Question You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains the identities shown in the following table. The tenant is onboarded to Permissions Management. You create the Azure resources shown in the following table. From Microsoft Entra Insights, which identity will be included in Accounts assigned to highly privileged roles, and which identity will be included in Service principals with privileged role assignments? Answer:

Exhibit

SC-300 question #389 exhibit

Answer Area

  • Accounts assigned to highly privileged rolesGroup1
    User1User2Group1Group2App1
  • Service principals with privileged role assignmentsApp1
    User1User2Group1Group2App1

Explanation

This question tests knowledge of Microsoft Entra Permissions Management Insights, specifically which identity types appear under 'Accounts assigned to highly privileged roles' versus 'Service principals with privileged role assignments'.

Approach. In Microsoft Entra Insights (part of Permissions Management), 'Accounts assigned to highly privileged roles' tracks human user accounts (such as Members or Guest users) that have been assigned highly privileged Azure AD/Entra roles like Global Administrator, Privileged Role Administrator, etc. 'Service principals with privileged role assignments' specifically tracks non-human identities - namely Service Principals (including Managed Identities and application service principals) - that have been granted privileged role assignments. Therefore, a human user identity (Member or Guest) assigned a highly privileged role appears in the first category, while a Service Principal (such as a Managed Identity or app registration service principal) with a privileged role assignment appears in the second category. The key distinction is: user accounts (human identities) go into the 'Accounts assigned to highly privileged roles' bucket, and service principals (workload/non-human identities) go into the 'Service principals with privileged role assignments' bucket.

Concept tested. Microsoft Entra Permissions Management Insights - understanding the distinction between user account identities tracked under 'Accounts assigned to highly privileged roles' and service principal identities tracked under 'Service principals with privileged role assignments', based on identity type (human user vs. service principal/managed identity).

Reference. https://learn.microsoft.com/en-us/entra/permissions-management/product-insights

Topics

#Permissions Management#Entra Insights#privileged role assignments#service principals

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice