exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 2 question 42 discussion

Actual exam question from Microsoft's SC-300
Question #: 42
Topic #: 2
[All SC-300 Questions]

You have a management group named Group1 that contains two Azure subscriptions named Sub1 and Sub2. The subscriptions are linked to a Microsoft Entra tenant that contains a user named User1.

You need to ensure that User1 can onboard Sub1 to Permissions Management. The solution must follow the principle of least privilege.

Which permission should you grant to User1?

  • A. Microsoft.Authorization/roleAssignments/read for Sub1
  • B. Microsoft.Authorization/roleAssignments/write for Group1
  • C. MicrosoftAuthorization/roleAssignments/write for Sub1
  • D. Microsoft.Authorization/roleAssignments/read for Group1
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
d1e85d9
3 months, 2 weeks ago
Selected Answer: C
In this scenario, User1 needs to onboard Sub1 to Permissions Management. This requires role assignment permissions at the subscription level. Analysis of Options: Correct Answer: C. Microsoft.Authorization/roleAssignments/write for Sub1 This permission grants User1 the necessary write access at the subscription level to onboard Sub1 to Permissions Management while adhering to the principle of least privilege.
upvoted 1 times
...
YesPlease
4 months ago
Selected Answer: A
Answer A) Least permission is on SUB1. Microsoft.Authorization/roleAssignments/read for Sub1 "C" is not even written in the right format https://learn.microsoft.com/en-us/entra/permissions-management/onboard-azure#explanation:~:text=This%20app%20requires%20%27reader%27%20permissions%20on%20the%20subscriptions
upvoted 3 times
YesPlease
3 months ago
Answer C I must have been wired on too many redbulls... you need write to onboard.
upvoted 1 times
...
rvln7
3 months, 2 weeks ago
Prerequisites To add Permissions Management to your Microsoft Entra tenant: You must have a Microsoft Entra user account and an Azure command-line interface (Azure CLI) on your system, or an Azure subscription. If you don't already have one, create a free account. You must have Microsoft.Authorization/roleAssignments/write permission at the subscription or management group scope to perform these tasks. If you don't have this permission, you can ask someone who has this permission to perform these tasks for you.
upvoted 1 times
...
csi_2025
3 months, 4 weeks ago
You are wrong. If you read the source you provide carefully you understand that when your tenant is onboarded an App is created and this App requires the reading permissions. In the Prerequisites its clearly stated what permission is required to do the task and logically its a write permission "You must have Microsoft.Authorization/roleAssignments/write permission at the subscription or management group scope to perform these tasks." The correct answer is C and most likely a typo by the creator of the question.
upvoted 3 times
...
...
Oskarma
4 months, 3 weeks ago
Selected Answer: C
The minimum priviledge level is at the subscription.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...