exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 1 question 83 discussion

Actual exam question from Microsoft's MS-500
Question #: 83
Topic #: 1
[All MS-500 Questions]

HOTSPOT
-

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.



You plan to enable Microsoft Defender for Endpoint role-based access control (RBAC).

You need to identify which users can enable RBAC in Microsoft Defender for Endpoint, and which users will lose access to Microsoft 365 Defender portal after RBAC in enabled.

Which users should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Kallely
6 months, 3 weeks ago
https://learn.microsoft.com/en-us/defender-endpoint/assign-portal-access
upvoted 1 times
...
RomanV
2 years ago
Correct answers: - User1 and User2 only - User4 only I hear you ask, why? "Initially, only those with Azure AD Global Administrator or Security Administrator rights will be able to create and assign roles in the Microsoft 365 Defender portal, therefore, having the right groups ready in Azure AD is important. Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Azure AD Security reader role) to lose access until they are assigned to a role." Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide
upvoted 4 times
...
formazionehs
2 years, 1 month ago
Can enable Microsoft Defender for Endpoint RBAC: User1 and User2 only https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide To enable the feature, you must have a Global Administrator role or Security Administrator role in Azure AD. Will lose access to Microsoft 365 Defender portal: User4 only Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Azure AD Security reader role) to lose access until they are assigned to a role.
upvoted 1 times
...
JoeP1
2 years, 2 months ago
Can enable Microsoft Defender for Endpoint RBAC is correct for User1 and User2 only because Microsoft says: "When you first log in to the Microsoft 365 Defender portal, you're granted either full access or read only access. Full access rights are granted to users with Security Administrator or Global Administrator roles in Azure AD. " The article is at: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide
upvoted 1 times
...
JoeP1
2 years, 2 months ago
User4(Security Reader) will definitely lose access to the Microsoft 365 Defender portal, but I am not sure about User3(Security Operator). I found a Microsoft article that confirms the loss of access:"Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Azure AD Security reader role) to lose access until they are assigned to a role." The article is at: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide
upvoted 2 times
...
msysadmin
2 years, 2 months ago
This part unclear for me: which users will lose access to Microsoft 365 Defender portal after RBAC in enabled? Not agree Security reader will lose access to Microsoft 365 Defender portal https://learn.microsoft.com/en-us/microsoft-365/security/defender/custom-roles?view=o365-worldwide
upvoted 1 times
...
EM1234
2 years, 2 months ago
ET admins are not even citing their pages for their answers on this one... like a few others I have seen.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago