Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam SC-300 topic 4 question 43 discussion

Actual exam question from Microsoft's SC-300
Question #: 43
Topic #: 4
[All SC-300 Questions]

You have a Microsoft 365 E5 subscription that contains a user named User1.

You need to ensure that User1 can create access reviews for Azure AD roles. The solution must use the principle of least privilege.

Which role should you assign to User1?

  • A. Privileged role administrator
  • B. Identity Governance Administrator
  • C. User administrator
  • D. User Access Administrator
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
kanag1
Highly Voted 9 months ago
Selected Answer: A
To create access reviews for Azure resources, you must be assigned to the Owner or the User Access Administrator role for the Azure resources. To create access reviews for Azure AD roles, you must be assigned to the Global Administrator or the Privileged Role Administrator role. https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-create-roles-and-resource-roles-review#prerequisites
upvoted 10 times
...
JuanZ
Most Recent 1 week, 3 days ago
Selected Answer: C
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task Least privileged roles by task in Microsoft Entra ID Create, update, or delete access review of a group or of an app- User Administrator
upvoted 1 times
...
klayytech
1 week, 6 days ago
Selected Answer: A
Microsoft Entra roles 1-Global administrator or 2-Privileged Role administrator
upvoted 1 times
...
razit
1 month, 1 week ago
Selected Answer: D
Based on https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews answer is D.
upvoted 1 times
...
Leuxah
3 months, 4 weeks ago
"To create access reviews for Microsoft Entra roles, you must be assigned to the Global Administrator or the Privileged Role Administrator role." https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review#prerequisites
upvoted 1 times
...
haazybanj
5 months, 2 weeks ago
Selected Answer: A
Access reviews: User Administrator (with the exception of access reviews of Azure or Microsoft Entra roles, which require Privileged Role Administrator). In this case, the Access review is for an Azure role which requires Privileged Role Administrator. https://learn.microsoft.com/en-us/entra/id-governance/identity-governance-overview?WT.mc_id=Portal-Microsoft_Azure_ELMAdmin#appendix---least-privileged-roles-for-managing-in-identity-governance-features
upvoted 2 times
...
Nyamnyam
5 months, 3 weeks ago
Selected Answer: A
Look at the table here https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews Specifically the row "Microsoft Entra roles"
upvoted 2 times
...
haazybanj
5 months, 4 weeks ago
Selected Answer: B
The correct answer is B. Identity Governance Administrator. The Identity Governance Administrator role allows users to create and manage access reviews for Azure AD roles, as well as other identity governance features. Privileged role administrator: This role allows users to manage all privileged roles in Azure AD. This is more permission than User1 needs, as they only need to be able to create access reviews for Azure AD roles.
upvoted 3 times
throwaway10188
3 months, 2 weeks ago
This is actually correct. If people are studying for this test they should know by now that if something is referencing Azure AD the test will Mean Azure Entra ID https://learn.microsoft.com/en-us/entra/id-governance/create-access-review
upvoted 1 times
throwaway10188
3 months ago
I stand corrected - To create access reviews for Azure resources, you must be assigned to the Owner or the User Access Administrator role for the Azure resources. To create access reviews for Microsoft Entra roles, you must be assigned to the Global Administrator or the Privileged Role Administrator role. Citation: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review#prerequisites
upvoted 1 times
...
...
...
itismadu
6 months, 1 week ago
Selected Answer: A
In Microsoft 365 (M365), users with specific roles can create access reviews for Azure Active Directory (Azure AD) roles. Here are the roles that can perform this task: Global Administrator: Global administrators have full access to all administrative features in Microsoft 365 and Azure AD, including the ability to create access reviews for Azure AD roles. Security Administrator: Security administrators have permissions to manage security-related settings in Azure AD, and they can create access reviews for Azure AD roles. Privileged Role Administrator: Privileged Role Administrators can manage assignments for privileged roles in Azure AD, including the ability to create access reviews for these roles.
upvoted 2 times
itismadu
6 months, 1 week ago
Chatgpt Response
upvoted 1 times
...
...
shuhaidawahab
6 months, 3 weeks ago
The correct answer is B. Identity Governance Administrator. According to the web search results, the Identity Governance Administrator role can create and manage access reviews for Azure AD roles1. The Privileged role administrator role can only manage Azure AD roles, but not access reviews2. The User administrator and User Access Administrator roles do not have permissions to create or manage access reviews3.
upvoted 3 times
...
rikicm
6 months, 3 weeks ago
Selected Answer: A
Global administrators and Privileged Role administrators can create reviews on role-assignable groups
upvoted 2 times
...
Reinhart68
7 months ago
Selected Answer: A
To create access reviews for Azure AD roles, you must be assigned to the Global Administrator or the Privileged Role Administrator role.
upvoted 2 times
...
EmnCours
8 months, 3 weeks ago
Selected Answer: A
A. Privileged role administrator
upvoted 3 times
...
FaizulHaque
8 months, 4 weeks ago
Should be B - Identity Governance Administrator (principle of least privilege)
upvoted 1 times
...
eternalenvy
9 months ago
Selected Answer: A
To create access reviews for Azure resources, you must be assigned to the Owner or the User Access Administrator role for the Azure resources. To create access reviews for Azure AD roles, you must be assigned to the Global Administrator or the Privileged Role Administrator role.
upvoted 3 times
eternalenvy
9 months ago
https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-create-roles-and-resource-roles-review?toc=%2Fazure%2Factive-directory%2Fgovernance%2Ftoc.json#prerequisites
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...