SC-401 · Question #41
Your company has offices in multiple countries. The company has a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management. You plan to perform the following actions: - In a…
The correct answer is C. an administrative unit. An administrative unit in Microsoft Entra ID is a container that scopes administrative role assignments to a specific subset of users, groups, and devices. By creating an administrative unit for Office1 and assigning User1 the Insider Risk Management Admins role scoped to that…
Question
Your company has offices in multiple countries. The company has a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management. You plan to perform the following actions:
- In a new country, open an office named Office1.
- Create a new user named User1.
- Deploy insider risk management to Office1.
- Add User1 to the Insider Risk Management Admins role group.
You need to ensure that User1 can perform insider risk management tasks for only the users and the devices in Office1. What should you create first?
Options
- Aa dynamic device group
- Ba dynamic user group
- Can administrative unit
- Da management group
How the community answered
(42 responses)- A2% (1)
- B7% (3)
- C79% (33)
- D12% (5)
Explanation
An administrative unit in Microsoft Entra ID is a container that scopes administrative role assignments to a specific subset of users, groups, and devices. By creating an administrative unit for Office1 and assigning User1 the Insider Risk Management Admins role scoped to that administrative unit, User1 can only perform insider risk management tasks for the users and devices within that unit-not for the entire tenant. Dynamic device groups and dynamic user groups are membership containers but do not restrict an admin's management scope. A management group is an Azure governance concept for organizing subscriptions, not for scoping admin permissions.
Topics
Community Discussion
No community discussion yet for this question.