exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 1 question 19 discussion

Actual exam question from Microsoft's MS-100
Question #: 19
Topic #: 1
[All MS-100 Questions]

Your company's Microsoft Azure Active Directory (Azure AD) tenant includes four users that are configured with the Privileged role administrator, the User administrator, the Security administrator, and the Billing administrator roles respectively.
A security group has been included in the tenant for the purpose of managing administrative accounts.
Which of the four roles can be used to add a user with the Security administrator role to the security group?

  • A. The Privileged role administrator role.
  • B. The User administrator role.
  • C. The Security administrator role.
  • D. The Billing administrator role.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zul_n
Highly Voted 3 years, 8 months ago
I'd say B is correct https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#user-administrator User Administrator Users with this role can create users, and manage all aspects of users with some restrictions (see the table), and can update password expiration policies. Additionally, users with this role can create and manage all groups.
upvoted 8 times
rfox321
3 years, 8 months ago
This is correct. Read the doc people
upvoted 5 times
...
...
Leo1905tti
Most Recent 1 year, 11 months ago
Selected Answer: A
Somente o administrador de função privilegiada pode tornar um grupo atribuível a funções administrativas
upvoted 1 times
...
JFFRY
2 years, 1 month ago
Selected Answer: B
B is correct
upvoted 1 times
...
Meebler
2 years, 2 months ago
Checked and tested: (B) Source : https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#user-administrator
upvoted 1 times
...
Feyenoord
2 years, 3 months ago
Selected Answer: A
Privileged Role Administrator Users with this role can manage role assignments in Azure Active Directory, as well as within Azure AD Privileged Identity Management. They can create and manage groups that can be assigned to Azure AD roles. In addition, this role allows management of all aspects of Privileged Identity Management and administrative units.
upvoted 1 times
Feyenoord
2 years, 3 months ago
I think I am switching to B. If you read carefully it's a security group which is used to managing accounts with privileges. Nowhere they are mentioning something about managing a role assignable group.
upvoted 1 times
...
...
hubran
2 years, 4 months ago
Selected Answer: A
Right answer is A. The question says about the group as "... purpose of managing administrative accounts". This clearly indicates that we are talking about a roles assigned group. If you read about that in https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept, they say that "Only Global Administrators and Privileged Role Administrators can create a role-assignable group"
upvoted 1 times
...
Don123
2 years, 4 months ago
A. The Privileged role administrator role. The Privileged role administrator role in Azure AD is the highest level of administrative access, and it has the ability to manage all aspects of an Azure AD tenant, including managing other administrators. This role can be used to add a user with the Security administrator role to the security group. The User administrator, Security administrator, and Billing administrator roles do not have the necessary permissions to manage other administrators and add them to the security group. It is important to note that, depending on the organization's security policies, adding users to the security group with the role of Security administrator may require approval from more than one privileged role administrator.
upvoted 2 times
...
MicrosoftBTN
2 years, 6 months ago
Using this link https://learn.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task by section Users there is Create guest users Guest inviter and User administrator
upvoted 1 times
...
JakeLi
2 years, 6 months ago
Tested it just now. B is correct.
upvoted 2 times
...
richardgnz
2 years, 7 months ago
I think the answer here is A https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept#how-are-role-assignable-groups-protected "By default, only Global Administrators and Privileged Role Administrators can manage the membership of a role-assignable group, but you can delegate the management of role-assignable groups by adding group owners." B - would be correct if they had been added to the group owners but this is not the default. We need to assume that the default settings are in place - therefore the answer must be A
upvoted 1 times
...
reastman66
2 years, 7 months ago
Correct answer is B User Administrator. Seems that there is a new feature where you can do a Run As for the different roles. For Priviledged Role , Security Administrator and Billing Administrator this is displayed when trying to add any user to a security group. You do not have appropriate permissions to edit this group. You should be a global administrator or user management administrator to manage this group.
upvoted 1 times
...
mllerena
2 years, 8 months ago
https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept#how-are-role-assignable-groups-protected By default, only Global Administrators and Privileged Role Administrators can manage the membership of a role-assignable group, but you can delegate the management of role-assignable groups by adding group owners.
upvoted 1 times
...
Sector12
2 years, 9 months ago
Selected Answer: A
The answer is A (tried and tested). The reason for this is logical, if you make any group role assignable, this could lead to privilege escalation. Role-assignable groups are designed to help prevent potential breaches by having the following restrictions: Only Global Administrators and Privileged Role Administrators can create a role-assignable group. The membership type for role-assignable groups must be Assigned and can't be an Azure AD dynamic group. Automated population of dynamic groups could lead to an unwanted account being added to the group and thus assigned to the role. https://docs.microsoft.com/en-us/azure/active-directory/roles/groups-concept
upvoted 1 times
Sector12
2 years, 9 months ago
Forgot one more point as per documentation: By default, only Global Administrators and Privileged Role Administrators can manage the membership of a role-assignable group, but you can delegate the management of role-assignable groups by adding group owners.
upvoted 2 times
...
Paolo2022
2 years, 7 months ago
This is not about assigning a role to a group (which is what only the priviledged role admin and global admin can do) - but about adding an admin user to a group. That is definitely possible for a user admin. So no further experiments - choose B!
upvoted 2 times
...
...
cluocal
3 years, 1 month ago
Selected Answer: B
B is correct.
upvoted 2 times
...
sandi412
3 years, 2 months ago
Tested.B is correct
upvoted 2 times
...
dudus999
3 years, 3 months ago
Assign group to role require special group. To that group you can assing member with user administrator role, you need to Global Admin or Priviliged role administrator
upvoted 2 times
dudus999
3 years, 3 months ago
*To that group you can't assing member with user administrator
upvoted 1 times
...
...
RazielLycas
3 years, 3 months ago
Both of them are correct if you read the role description "Privileged Role Administrator: Users with this role can manage role assignments in Azure Active Directory, as well as within Azure AD Privileged Identity Management. They can create and manage groups that can be assigned to Azure AD roles. In addition, this role allows management of all aspects of Privileged Identity Management and administrative units." "User Administrator: Users with this role can create users, and manage all aspects of users with some restrictions (see the table), and can update password expiration policies. Additionally, users with this role can create and manage all groups. This role also includes the ability to create and manage user views, manage support tickets, and monitor service health. User Administrators don't have permission to manage some user properties for users in most administrator roles. Admins with this role do not have permissions to manage MFA or manage shared mailboxes. The roles that are exceptions to this restriction are listed in the following table."
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...