exam questions

Exam AZ-303 All Questions

View all questions & answers for the AZ-303 exam

Exam AZ-303 topic 6 question 23 discussion

Actual exam question from Microsoft's AZ-303
Question #: 23
Topic #: 6
[All AZ-303 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant that contains three global administrators named Admin1, Admin2, and Admin3.
The tenant is associated to an Azure subscription. Access control for the subscription is configured as shown in the Access control exhibit. (Click the Exhibit tab.)

You sign in to the Azure portal as Admin1 and configure the tenant as shown in the Tenant exhibit. (Click the Exhibit tab.)

For each of the following statement, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gssd4scoder
Highly Voted 3 years, 11 months ago
Question 1-2: Y Y -> Global admins can assign owner to other users in IAM (tested). Question 3: N -> since it's not specified that Admin 2 is contributor of the subscription that user can't create a resource group. Of course he can give himself the permission.
upvoted 9 times
ZodiaC
3 years, 7 months ago
100% Correct
upvoted 1 times
...
...
shafqat
Highly Voted 3 years, 8 months ago
When you check "Global admin can manage ..." you elevate currently logged in admin to User Access Administrator, not the all admins. So, answer for 2 is no because Admin1 is User Access Administrator, Admin 2 is noone, and Admin 3 is an owner. YES NO NO
upvoted 7 times
...
sam
Most Recent 3 years, 5 months ago
Answer is Y Y Y. simple!
upvoted 1 times
[Removed]
3 years, 5 months ago
If it's so simple then please explain your logic.
upvoted 5 times
...
...
robn
3 years, 6 months ago
Actual setting in AAD is called "can manage access to all Azure subscriptions and management groups in this tenant" - if this is set to yes, all GAs can manage user permissions on Azure. By doing so they can delegate all RBAC roles on the Subscriptions associated with given Tenant. SO it would be Yes, Yes and Yes (third answer would require two steps, first grant yourself Owner on Subscription, then deploy a Resource Group).
upvoted 1 times
...
syu31svc
3 years, 9 months ago
Yes No No https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin As a Global Administrator in Azure Active Directory (Azure AD), you might not have access to all subscriptions and management groups in your directory When you elevate your access, you will be assigned the User Access Administrator role in Azure at root scope -> means you have the full complete permission
upvoted 3 times
...
Ario
3 years, 9 months ago
if you are a Global Administrator in Azure AD, you can assign yourself access to all Azure subscriptions and management groups in your directory
upvoted 1 times
...
hoangton
3 years, 10 months ago
Given answer is correct : Y, N, N When you set the toggle to Yes, you are assigned the User Access Administrator role in Azure RBAC at root scope (/). This grants you permission to assign roles in all Azure subscriptions and management groups associated with this Azure AD directory. This toggle is only available to users who are assigned the Global Administrator role in Azure AD. Admin2 don't config as Admin1 do so N and N Reference: https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin
upvoted 2 times
certpro
3 years, 10 months ago
Given answer is Correct: by default, the Global Administrator (Admin2, Admin3) doesn't have access to Azure resources.
upvoted 1 times
...
...
Rens19991
3 years, 11 months ago
From other user: I think, Yes, No, No. https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin As a Global Administrator in Azure Active Directory (Azure AD), you might not have access to all subscriptions and management groups in your directory. Azure AD and Azure resources are secured independently from one another. That is, Azure AD role assignments do not grant access to Azure resources, and Azure role assignments do not grant access to Azure AD. However, if you are a Global Administrator in Azure AD, you can assign yourself access to all Azure subscriptions and management groups in your directory. Admin1 grants itself such access, so he can manage any user and any group/role and user assignment to any group/role.
upvoted 3 times
rdemontis
3 years, 10 months ago
thanks for explanation!!
upvoted 1 times
...
Biden
3 years, 10 months ago
Since all 3 Admins are Global Admins, whats stopping them to login to the Azure portal and grant them privileges to the subscription, and then grant access ??
upvoted 3 times
...
tita_tovenaar
3 years, 10 months ago
Agreed, So why is it not yes-yes-yes? I see no obstructions for any of the statements
upvoted 1 times
...
...
Tripp_F
3 years, 11 months ago
From another user: When you check "Global admin can manage ..." you elevate currently logged in admin to User Access Administrator, not the all admins. So, answer for 2 is no because Admin1 is User Access Administrator, Admin 2 is noone, and Admin 3 is an owner. YES NO NO
upvoted 3 times
...
Linus0
3 years, 11 months ago
https://www.examtopics.com/discussions/microsoft/view/5902-exam-az-103-topic-1-question-9-discussion/
upvoted 1 times
...
BlackZeros
3 years, 11 months ago
I think answer is Y Y Y ... Owner role engulfs all Contributor access and user access management role, therefore admin2 can create the RG.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...