exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 1 question 82 discussion

Actual exam question from Microsoft's MS-500
Question #: 82
Topic #: 1
[All MS-500 Questions]

You have a Microsoft 365 E5 subscription that contains a user named User1.

You need to ensure that User1 can configure an Azure Active Directory (Azure AD) Identity Protection user risk policy and receive Azure AD Identity Protection alerts. The solution must use the principle of least privilege.

Which role should you assign to User1?

  • A. Security Operator
  • B. Identity Governance Administrator
  • C. Security Administrator
  • D. Security Reader
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AVN1711
1 year, 9 months ago
Selected Answer: A
I think A-Security Operator is the right answer. in the Permissions>Manage all it has -Create and delete all resources, and read and update standard properties in ‎Azure AD Identity Protection‎
upvoted 1 times
...
Ndaiga
2 years ago
Selected Answer: C
Security Admin is the correct answer. Security operator can't configure policies
upvoted 1 times
...
Jay_ITN
2 years, 1 month ago
The Identity Governance Administrator role in Microsoft 365 provides the necessary permissions to configure and manage identity-related policies and features, including Azure AD Identity Protection. This role allows User1 to configure user risk policies and receive alerts specifically related to Azure AD Identity Protection. Assigning User1 the Identity Governance Administrator role ensures that they have the appropriate level of access and control over identity protection without granting them broader security administration privileges (such as the Security Administrator role) that may exceed their requirements.
upvoted 1 times
...
kmk_01
2 years, 3 months ago
Selected Answer: C
Yes it's C. Only Global Admins and Security Admins can configure Identity Protection policies. https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection#required-roles
upvoted 2 times
...
rtis16
2 years, 4 months ago
Selected Answer: C
Agreed with EM1234, it should be C.
upvoted 2 times
...
msysadmin
2 years, 4 months ago
Selected Answer: C
Answer is C https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#security-operator
upvoted 2 times
...
EM1234
2 years, 4 months ago
I think it should be C. This is from the docs on the security operator built in role: All permissions of the Security Reader role Perform all Identity Protection operations except for configuring or changing risk-based policies, resetting passwords, and configuring alert e-mails. https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#security-operator
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...