exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 6 question 3 discussion

Actual exam question from Microsoft's SC-300
Question #: 3
Topic #: 6
[All SC-300 Questions]

HOTSPOT -
You need to identify which roles to use for managing role assignments. The solution must meet the delegation requirements.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-portal https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sapien45
Highly Voted 2 years, 4 months ago
For Azure AD roles in Privileged Identity Management, only a user who is in the Privileged Role Administrator or Global Administrator role can manage assignments for other administrators. Global Administrators, Security Administrators, Global Readers, and Security Readers can also view assignments to Azure AD roles in Privileged Identity Management. For Azure resource roles in Privileged Identity Management, only a subscription administrator, a resource Owner, or a resource User Access administrator can manage assignments for other administrators. Users who are Privileged Role Administrators, Security Administrators, or Security Readers do not by default have access to view assignments to Azure resource roles in Privileged Identity Management. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure
upvoted 20 times
jack987
1 year, 10 months ago
This is very too to explain the answer. Thanks!
upvoted 2 times
jack987
1 year, 10 months ago
This is very good* to explain the answer. Thanks!
upvoted 1 times
...
...
...
leeuw86
Highly Voted 3 years, 4 months ago
that's correct
upvoted 7 times
...
Sneekygeek
Most Recent 9 months ago
Box1: Privileged Role Administrator Box2: Global Admin The following Article says you need Microsoft.Authorization/roleAssignments/write to assign Azure roles. https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps#step-4-check-your-prerequisites If you check all the built-in roles that have that permission, none are listed as options other than global admin which would have permission to manage the whole subscription. https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles#user-access-administrator
upvoted 1 times
belyo
7 months, 3 weeks ago
https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/general#user-access-administrator:~:text=types%2C%20except%20secrets.-,Microsoft.Authorization/*,-Manage%20authorization what are you mentioning is included in user access admin
upvoted 1 times
...
Alcpt
5 months, 1 week ago
no. the delegation reqments says use Polp. hence box 1 = Privileged Role Administrator box 2 = User Access administrator
upvoted 1 times
...
...
dule27
1 year, 3 months ago
Azure AD build-in role: Privileged role Administrator Azure build-in role: User Access Administrator
upvoted 2 times
...
Nonyabuz
2 years, 1 month ago
Step 4. Check your prerequisites To assign roles, you must be signed in with a user that is assigned a role that has role assignments write permission, such as Owner or ***User Access Administrator*** at the scope you are trying to assign the role. Similarly, to remove a role assignment, you must have the role assignments delete permission. Microsoft.Authorization/roleAssignments/write Microsoft.Authorization/roleAssignments/delete If your user account doesn't have permission to assign a role within your subscription, you see an error message that your account "does not have authorization to perform action 'Microsoft.Authorization/roleAssignments/write'." In this case, contact the administrators of your subscription as they can assign the permissions on your behalf. https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps
upvoted 1 times
...
RandomNickname
2 years, 4 months ago
Given answer is correct. For Azure AD role see; https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference And the subsequent link for; https://docs.microsoft.com/en-us/azure/active-directory/roles/manage-roles-portal For Azure built-in role see; https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles And the subsequent link for; https://docs.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps
upvoted 2 times
...
Jun143
2 years, 7 months ago
just pass the exam today. This came in the question.
upvoted 2 times
...
TheGuy
2 years, 7 months ago
Second question is referring to Azure built-in roles and NOT Azure AD built-in roles, hence user access administrator Azure Roles: https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles Azure AD Roles: https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
upvoted 3 times
...
Bulldozzer
2 years, 7 months ago
Since the user access administrator role does not exist. For me, it is the Privileged Administrator role that should be selected for both answers.
upvoted 2 times
chikorita
1 year, 7 months ago
Azure AD: User Administrator Azure RBAC: User Access Administrator
upvoted 1 times
...
Paimon
2 years, 7 months ago
It does exist for Azure......not Azure AD. But it can't manage Azure roles - only access to resources. So you still got the correct answer. Global admin can also do both.
upvoted 2 times
Paimon
2 years, 7 months ago
......but PIM is the requirement, so privileged admin role is correct.
upvoted 1 times
...
...
...
Pravda
2 years, 9 months ago
On the exam 1/20/2022
upvoted 1 times
...
melatocaroca
3 years, 3 months ago
Requirements. Delegation Requirements Delegate the management of privileged roles by using Azure AD Privileged Identity Management (PIM). Prevent nonprivileged users from registering applications in the litware.com Azure AD tenant. Use custom catalogs and custom programs for Identity Governance. Ensure that User1 can create enterprise applications in Azure AD. Use the principle of least privilege. (To assign Azure roles, you must have User Access Administrator or Owner) For Azure AD roles in Privileged Identity Management, only a user who is following roles • Privileged Role Administrator o or • Global Administrator can manage assignments for other administrators For Azure AD roles in Privileged Identity Management view assignments only a user who is following roles. • Global Administrators, • Security Administrators, • Global Readers • Security Readers User administrator Create and manage all aspects of users and groups, manage support tickets, monitor service health, Change passwords for users, Helpdesk administrators, and other User Administrators
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago