exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 1 question 36 discussion

Actual exam question from Microsoft's SC-300
Question #: 36
Topic #: 1
[All SC-300 Questions]

HOTSPOT -

You have a Microsoft 365 tenant that has 5,000 users. One hundred of the users are executives. The executives have a dedicated support team.

You need to ensure that the support team can reset passwords and manage multi-factor authentication (MFA) settings for only the executives. The solution must use the principle of least privilege.

Which object type and Azure Active Directory (Azure AD) role should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Halwagy
Highly Voted 2 years, 3 months ago
Correct Answer: Object Type: Administrative Unit Role: Authentication administrator
upvoted 81 times
...
skbudhram
Highly Voted 2 years, 2 months ago
Sheesh this site has a lot of wrong answers, what's the point even ..
upvoted 33 times
...
Davito
Most Recent 5 months, 4 weeks ago
The key part of this question is the requirement that these settings be changed or managed for ONLY the executives. From the who can reset passwords page (https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-assign-roles#roles-that-can-be-assigned-with-administrative-unit-scope) it notes that additional restrictions apply to roles scoped to administrative units. Once you create an AU there is then a smaller selection of eligible roles that can be assigned, and the further restrictions page (https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-assign-roles#roles-that-can-be-assigned-with-administrative-unit-scope) states that the Authentication Administrator "Has access to view, set, and reset authentication method information for any non-admin user in the assigned administrative unit ONLY." This accomplishes our goal of ensuring the administrator permissions would only extend to members of of the AU (executives). Therefore the answer is: Administrative Unit & Authentication Administrator
upvoted 5 times
...
BRZSZCL
6 months, 1 week ago
To meet the requirement of allowing the support team to reset passwords and manage MFA settings for only the executives while adhering to the principle of least privilege, you can follow this approach: Object Type: Azure AD Group You should use an Azure AD group to define the executives as a specific set of users. Create a group that contains only the 100 executives, which will limit the scope of operations to this group. Azure AD Role: Authentication Administrator Assign the Authentication Administrator role to the support team for this specific group. This role allows resetting passwords, managing multi-factor authentication (MFA) settings, and configuring authentication policies, but only for the users within the assigned scope (in this case, the executives group). Summary: Object Type: Azure AD Group Azure AD Role: Authentication Administrator
upvoted 2 times
josemariamr
4 months, 4 weeks ago
Copilot: To ensure that the support team can reset passwords and manage multi-factor authentication (MFA) settings for only the executives while adhering to the principle of least privilege, you should use the following: Object Type: Create a group in Azure AD that includes only the executives. Azure AD Role: Assign the Authentication Administrator role to the support team members. This role allows them to reset passwords and manage MFA settings, but only for users who are assigned to specific roles or groups. By creating a group for the executives and assigning the Authentication Administrator role to the support team, you ensure that the support team has the necessary permissions to manage only the executives' accounts without having broader access
upvoted 1 times
...
...
hml_2024
7 months, 2 weeks ago
To ensure that the support team can reset passwords and manage multi-factor authentication (MFA) settings for only the executives while adhering to the principle of least privilege, you should use: Object Type: 1. An Administrative Unit Role: 1. Authentication Administrator
upvoted 3 times
...
MISCOLO
11 months ago
no such thing as a custom admin role
upvoted 2 times
SamuelPerezMartin
9 months, 2 weeks ago
Microsoft Entra allows you to create custom admin roles.
upvoted 3 times
...
...
HartMS
1 year ago
AU Authentication Administrator
upvoted 3 times
...
b0tag
1 year, 8 months ago
Should be Administrative Unit Helpdesk administrator - The Authentication Administrator role is less privileged than the Helpdesk Administrator role The Authentication Administrator role has permissions to manage authentication methods and password reset whereas the Helpdesk Administrator role has permissions to manage passwords, groups, and users.
upvoted 5 times
DasChi_cken
1 year, 6 months ago
You are right regarding the difference between helpdesk and authentication Admin.... Therefore the answer is: Administrative unit Authentication Admin The Support Team shall only reset MFA and Passworts and regarding least privileg this IS the best role
upvoted 5 times
...
...
EmnCours
1 year, 9 months ago
Object Type: Administrative Unit Role: Authentication administrator
upvoted 4 times
...
dule27
1 year, 9 months ago
Object Type: An Administrative Unit Role: Authentication Administrator
upvoted 4 times
...
b233f0a
1 year, 10 months ago
Role: Authentication Administrator - https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#authentication-administrator - "Set or reset any authentication method (including passwords) for non-administrators"
upvoted 2 times
...
dule27
1 year, 10 months ago
Object Type: An administrative unit Role: Authentication administrator
upvoted 6 times
...
ShoaibPKDXB
1 year, 11 months ago
Correct: Object Type: An Administrative Unit Role: Authentication Administrator
upvoted 2 times
...
rajbne
2 years ago
Please update final answer
upvoted 3 times
...
Remus999
2 years ago
Authentication Administrator is the least privileged role to manage MFA as per https://learn.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task#multi-factor-authentication
upvoted 3 times
...
Akakentavr
2 years, 3 months ago
As well regarding the Authentication administrator or Helpdesk administrator options pay attention to "executives" in our case and Helpdesk administrator -Can reset passwords for non-administrators and Helpdesk Administrators. So Authentication administrator is our choice
upvoted 6 times
...
jojoseph
2 years, 3 months ago
Object Type: Administrative Unit Role: Authentication administrator
upvoted 1 times
ExamStudy68
2 years ago
Maybe it's by design to force discussion and make you think about it or look it up... Not sure really.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago