exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 116 discussion

Actual exam question from Microsoft's MS-102
Question #: 116
Topic #: 1
[All MS-102 Questions]

You have a Microsoft 365 E5 subscription that uses Endpoint security.

You need to create a group and assign the Endpoint Security Manager role to the group.

Which type of group can you use?

  • A. Microsoft 365 only
  • B. security only
  • C. mail-enabled security and security only
  • D. mail-enabled security, Microsoft 365, and security only
  • E. distribution, mail-enabled security, Microsoft 365, and security
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cb0900
Highly Voted 1 year, 10 months ago
Selected Answer: D
In a test tenant, I was able to add mail-enabled security, M365 and security groups to an EndPoint Security Manager role assignment. Add Role Assignment -> Admin Groups...
upvoted 22 times
daye
1 year, 8 months ago
tricky question because based on this article you need to use a security group, but indeed you can select a M356 group (but It won't work) https://learn.microsoft.com/en-us/mem/intune/fundamentals/role-based-access-control#role-assignments
upvoted 1 times
daye
1 year, 8 months ago
So I will use B because you need to apply the role successfully
upvoted 1 times
...
...
...
Darekmso
Highly Voted 1 year, 9 months ago
Selected Answer: D
Checked : From endopint manager > tenant admin > roles > open "endpoint decurity manager" > assignments > ..... you can choose M365, security & mail-enabled group
upvoted 9 times
rass1981
1 year, 6 months ago
I did the same and can confirm all options in D can be chosen.
upvoted 2 times
...
...
WASDowningpower
Most Recent 1 month, 2 weeks ago
Selected Answer: C
As of May 2025, C (mail-enabled security and security only) is the correct answer. I tested it in my Dev-Tenant
upvoted 1 times
...
IgoKostadin
1 month, 3 weeks ago
Selected Answer: B
The correct answer is B. Security only. Explanation: - The Endpoint Security Manager role is managed through role-based access control (RBAC) in Microsoft Intune. - Security groups are the only group type that can be used for assigning RBAC roles in Microsoft Endpoint Manager. - Mail-enabled security groups, Microsoft 365 groups, and distribution groups cannot be used for RBAC role assignments in Endpoint security.
upvoted 1 times
...
bnijhofNL
3 months, 1 week ago
To assign roles (like Endpoint Security Manager) in Microsoft Entra ID (formerly Azure AD), you can only use security groups — and not mail-enabled or Microsoft 365 groups. Security groups are used to control access and assign roles/permissions. Role assignments (like Azure AD roles or Microsoft 365 admin roles) can only be assigned to users or security groups.
upvoted 1 times
...
MToo
6 months ago
There are no right answers. Only Security groups and M365 groups can have assigned roles. You can't create a mail-enabled security group in Entra ID. So right answer is F: Security and Microsoft 365 groups.
upvoted 1 times
...
Frank9020
8 months, 1 week ago
Selected Answer: C
Microsoft 365 groups cannot be used for role assignments, so including them in this answer is incorrect.
upvoted 1 times
Frank9020
8 months, 1 week ago
Microsoft 365 groups are designed primarily for collaboration within Microsoft 365 apps, like Teams, SharePoint, and Outlook, rather than for security or administrative role assignments.
upvoted 1 times
...
...
justITtopics
9 months, 1 week ago
Selected Answer: D
The correct option is D, because it is the only answer that contains both groups to which roles can be assigned: To assign a role to a group, you must create a new security or Microsoft 365 group with the isAssignableToRole property set to true https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/groups-concept
upvoted 1 times
...
wael_kodmani
10 months, 3 weeks ago
copilot and Chatgpt choose security only because you can't use Microsoft 365 and mail-enabled security for role assignment!
upvoted 2 times
...
mikl
1 year, 2 months ago
Selected Answer: D
You CAN use : D. mail-enabled security, Microsoft 365, and security only But recommended would be : B. security only. But question here is about what you CAN do.
upvoted 1 times
...
Shuihe
1 year, 7 months ago
D https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/groups-concept
upvoted 1 times
...
Christianbrivio1991
1 year, 7 months ago
dovrebbe essere la B https://learn.microsoft.com/it-it/microsoft-365/admin/create-groups/compare-groups?view=o365-worldwide
upvoted 1 times
Christianbrivio1991
1 year, 7 months ago
Sorry, the correct answer is C
upvoted 1 times
...
...
TP447
1 year, 8 months ago
Correct answer is C for me - Mail Enabled Security and Security Group types can both be used for delegation here.
upvoted 1 times
...
sergioandreslq
1 year, 8 months ago
I tested in my tenant from Intune to assign this role, I was able only to choose: mail-enabled security and security only. When I tried MS365 or Distribution group, there is not any option to choose. So, I will choose option C.
upvoted 5 times
...
Darekmso
1 year, 9 months ago
Selected Answer: B
Looks like B for me -> https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept#how-role-assignments-to-groups-work
upvoted 2 times
Darekmso
1 year, 9 months ago
Update it should be D -> From endopint manager > tenant admin > roles > open "endpoint decurity manager" > assignments > ..... you can choose M365, security & mail-enabled group
upvoted 2 times
...
...
MarkusSan
1 year, 9 months ago
Selected Answer: D
https://www.examtopics.com/discussions/microsoft/view/80188-exam-ms-100-topic-5-question-64-discussion/
upvoted 5 times
...
RJTW070
1 year, 10 months ago
Selected Answer: B
To create a group and assign the Endpoint Security Manager role to the group, you can use a role-assignable group. A role-assignable group is a type of Azure AD security group that can be assigned to a role in Microsoft Endpoint Manager1. You can create a role-assignable group by using the Azure portal, PowerShell, or Microsoft Graph2.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...