Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft Exam SC-100 Topic 6 Question 36 Discussion

Actual exam question for Microsoft's SC-100 exam
Question #: 36
Topic #: 6
[All SC-100 Questions]

You have an Azure AD tenant that contains 10 Windows 11 devices and two groups named Group1 and Group2. The Windows 11 devices are joined to the Azure AD tenant and are managed by using Microsoft Intune.

You are designing a privileged access strategy based on the rapid modernization plan (RaMP). The strategy will include the following configurations:

* Each user in Group1 will be assigned a Windows 11 device that will be configured as a privileged access device.

* The Security Administrator role will be mapped to the privileged access security level.

* The users in Group1 will be assigned the Security Administrator role.

* The users in Group2 will manage the privileged access devices.

You need to configure the local Administrators group for each privileged access device. The solution must follow the principle of least privilege.

What should you include in the solution?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

Cherelle
11 days ago
Hmm, I don't know. Option B with the Windows LAPS emulation mode sounds interesting. That could be a way to manage the local admin passwords without having to directly add users to the local Administrators group. Might be worth considering.
upvoted 0 times
...
Golda
12 days ago
Yeah, I'm with you guys on that one. Option C covers all the bases - it gives Group2 the necessary access to manage the devices, while also giving the Security Administrators the privileges they need on their assigned devices. Plus, it adheres to the principle of least privilege, which is key.
upvoted 0 times
...
Mirta
13 days ago
I agree, option C seems to be the most comprehensive solution. Adding Group2 to the local Administrators group makes sense, as they'll be managing the privileged access devices. And adding the user with the Security Administrator role to their assigned device's local Administrators group is also a good call.
upvoted 0 times
...
Vanda
14 days ago
Hmm, this question seems a bit tricky. We need to configure the local Administrators group for the privileged access devices, while following the principle of least privilege. I'm thinking option C might be the way to go here.
upvoted 0 times
...

Save Cancel