nerdexam
Microsoft

SC-300 · Question #86

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. You plan to implement Azure AD Identity Protection. Which users can configur

The correct answer is User1 can configure the user risk policy = Yes; User2 can configure the user risk policy = No; User3 can configure the user risk policy = Yes; User4 can configure the user risk policy = No; User1 can view the risky users report = No; User2 can view the risky users report = No; User3 can view the risky users report = Yes; User4 can view the risky users report = Yes. This question tests knowledge of Azure AD Identity Protection role-based access control, specifically which Azure AD roles have permissions to configure risk policies versus view risky users reports.

Submitted by ashley.k· Mar 6, 2026Implement authentication and access management

Question

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. You plan to implement Azure AD Identity Protection. Which users can configure the user risk policy, and which users can view the risky users report? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point. Answer:

Exhibits

SC-300 question #86 exhibit 1
SC-300 question #86 exhibit 2

Answer Area

  • User1 can configure the user risk policyYes
  • User2 can configure the user risk policyNo
  • User3 can configure the user risk policyYes
  • User4 can configure the user risk policyNo
  • User1 can view the risky users reportNo
  • User2 can view the risky users reportNo
  • User3 can view the risky users reportYes
  • User4 can view the risky users reportYes

Explanation

This question tests knowledge of Azure AD Identity Protection role-based access control, specifically which Azure AD roles have permissions to configure risk policies versus view risky users reports.

Approach. Azure AD Identity Protection requires specific roles for different tasks. To CONFIGURE the user risk policy, a user needs the Security Administrator or Global Administrator role - standard Security Reader or other limited roles are insufficient for policy configuration. To VIEW the risky users report, roles including Security Administrator, Security Reader, Global Administrator, and Global Reader all have read access to Identity Protection reports. In a typical exam scenario with users assigned roles like Global Administrator, Security Administrator, and Security Reader: Global Admin and Security Admin can configure the user risk policy, while Global Admin, Security Admin, and Security Reader (plus Global Reader) can view the risky users report. The key distinction is that read-only roles (Security Reader, Global Reader) can VIEW reports but cannot CONFIGURE policies.

Concept tested. Azure AD Identity Protection role-based access control - understanding which roles (Global Administrator, Security Administrator, Security Reader, Global Reader) have permissions to configure risk policies versus viewing risky users/sign-in risk reports within Azure AD Identity Protection.

Reference. https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection#required-roles

Topics

#Identity Protection#user risk policy#RBAC#risky users report

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice