You have a Microsoft 365 subscription that contains a user named User1.
You need to ensure that User1 can create access reviews for Azure AD roles. The solution must use the principal of least privilege.
Which role should you assign to User1?
The question asks which role allows a user to create access reviews for Azure AD roles using the principle of least privilege.
Privileged Role Administrator can manage all role assignments and access reviews, but it has more privileges than needed.
Identity Governance Administrator manages entitlement management and access packages, not Azure AD roles directly.
User Administrator can manage users but not access reviews for roles.
User Access Administrator is the correct least-privilege role, as it allows management of access reviews related to Azure AD roles and role-assignable groups.
From Microsoft Documentation (SC-300 Exam Guide):
''The User Access Administrator role allows management of access reviews and permissions for Azure AD roles and resources using the least-privileged approach.''
Currently there are no comments in this discussion, be the first to comment!