You need to provide a user the ability Security defaults and create Conditional Access policies. The solution must use the principle of least privilege.
https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/security-defaults
To configure security defaults in your directory, you must be assigned at least the Security Administrator role.
Microsoft must have changed it, your link now says "To configure security defaults in your directory, you must be assigned at least the Conditional Access Administrator role."
^^^ This guy knows stuff.
"To enable security defaults (or confirm they're already enabled)
Sign in to the Microsoft Entra admin center as least a Security Administrator."
https://learn.microsoft.com/en-us/microsoft-365/business-premium/m365bp-turn-on-mfa?view=o365-worldwide&tabs=secdefaults
Conditional Access Admin can change only CAPs, named locations and auth contexts. No security defaults.
B appears to be correct:
To set up security defaults and create Conditional Access policies, a user requires the Conditional Access Administrator or Security Administrator role1. However, the Security Reader or Global Reader role is sufficient if the purpose is solely to read policies1.
To provide a user with the ability to manage Security defaults and create Conditional Access policies while adhering to the principle of least privilege, you should assign the Conditional Access Administrator role (Option B). This role grants the necessary permissions without the broader access associated with the Global Administrator role
correction "To configure security defaults in your directory, you must be assigned at least the Conditional Access Administrator role."
https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
Conditional Access Administrator: This role allows the user to manage Conditional Access policies and other identity-related configurations. It adheres to the principle of least privilege because the user is given only the permissions required to manage Conditional Access settings.
https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults#enabling-security-defaults
To configure security defaults in your directory, you must be assigned at least the Security Administrator role. By default the first account in any directory is assigned a higher privileged role known as Global Administrator.
https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults#enabling-security-defaults - To configure security defaults in your directory, you must be assigned at least the Security Administrator role. By default the first account in any directory is assigned a higher privileged role known as Global Administrator.
correction "To configure security defaults in your directory, you must be assigned at least the Conditional Access Administrator role."
https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
Correct answer is C: Security Administrator. Why? Because the Conditional Access Admin can only change or create or delete CA's and dos not have security defaults in it. Only the Security Admin or Global Admin have this. But the question says "LEAST privilege" so it's C. in this case.
Learn more about Azure build-in roles here:
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#security-administrator
correction "To configure security defaults in your directory, you must be assigned at least the Conditional Access Administrator role."
https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
It is possible with B or C, however B has fewer privileges - https://learn.microsoft.com/en-us/answers/questions/1462298/configure-security-defaults-which-role-can-do-this
as per your link its only possible with Security Administrator.
To configure security defaults in your directory, you must be assigned at least the Security Administrator role. By default the first account in any directory is assigned a higher privileged role known as Global Administrator.
To configure security defaults in your directory, you must be assigned at least the Security Administrator role. By default the first account in any directory is assigned a higher privileged role known as Global Administrator. - from your link
correction "To configure security defaults in your directory, you must be assigned at least the Conditional Access Administrator role."
https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
Conditional Access Admin CANNOT configure Security Defaults. C fulfils both requirements.
Source: https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults#enabling-security-defaults
To configure security defaults in your directory, you must be assigned at least the Security Administrator role.
correction "To configure security defaults in your directory, you must be assigned at least the Conditional Access Administrator role."
https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
Answer is C:
https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
To configure security defaults in your directory, you must be assigned at least the Security Administrator role.
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#security-administrator
Conditional Access Admin role can only edit Conditional Access related settings, they cannot edit Security Defaults
B. Conditional Access Administrator.
The Conditional Access Administrator role allows users to manage Azure Active Directory Conditional Access policies without giving them broader administrative permissions that come with roles like Global Administrator. This aligns with the principle of least privilege by granting only the necessary permissions for the task.
This section is not available anymore. Please use the main Exam Page.MD-102 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Stuckbear
Highly Voted 1 year, 9 months agoFrederikd
4 months, 3 weeks agoBurkidur
1 year, 4 months agopicho707
Highly Voted 1 year, 9 months agojzmirus2
Most Recent 3 months, 3 weeks agocorrection
5 months ago6060
5 months, 3 weeks agoSeek12
6 months, 1 week agoFriscini
6 months, 2 weeks agoTr619899
7 months agoTr619899
6 months agoNav90
8 months agomartinods
8 months, 2 weeks agocorrection
5 months agoRomanV
9 months, 1 week agocorrection
5 months agoEUC_PRO
9 months, 3 weeks agoNav90
8 months agomartinods
8 months, 2 weeks agocorrection
5 months agoPollosor
10 months, 2 weeks agooopspruu
11 months, 2 weeks agocorrection
5 months agoPrasis
11 months, 3 weeks agoda_terminator
1 year agoCJL324
1 year, 1 month ago