Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft SC-300 Exam - Topic 4 Question 128 Discussion

You have an Azure AD tenant that contains an access package named Package1 and a user named User1. Package1 is configured as shown in the following exhibit.You need to ensure that User1 can modify the review frequency of Package1. The solution must use the principle of least privilege.Which role should you assign to User1?
B) User administrator
A) Privileged role administrator
C) External Identity Provider administrator
D) Security administrator

Microsoft SC-300 Exam - Topic 4 Question 128 Discussion

Actual exam question for Microsoft's SC-300 exam
Question #: 128
Topic #: 4
[All SC-300 Questions]

You have an Azure AD tenant that contains an access package named Package1 and a user named User1. Package1 is configured as shown in the following exhibit.

You need to ensure that User1 can modify the review frequency of Package1. The solution must use the principle of least privilege.

Which role should you assign to User1?

Show Suggested Answer Hide Answer
Suggested Answer: B

This question refers to Azure AD Entitlement Management under Identity Governance. The goal is to let User1 modify the review frequency (i.e., Access Reviews) for an existing access package named Package1, following the principle of least privilege.

In Azure AD, the ability to create and manage access packages, catalogs, and access reviews is granted through certain administrative roles:

Global Administrator and Identity Governance Administrator --- Full control over all Identity Governance settings.

Catalog Owner or Access Package Manager --- Manage access packages and settings within a catalog.

User Administrator --- Can configure access reviews and manage users, groups, and limited governance settings.

Privileged Role Administrator, Security Administrator, and External Identity Provider Administrator --- Have no direct control over access review settings in Entitlement Management.

From Microsoft documentation (''Azure AD Entitlement Management Delegation and Roles''):

''A user administrator can manage access reviews and entitlement management settings for the directory and assigned catalogs, including adjusting the review frequency or review settings.''

Thus, to modify the Access Review configuration (frequency, reviewers, etc.) in Package1, the User Administrator role provides the minimum necessary privilege without granting excessive permissions like Identity Governance Administrator or Global Administrator.


Contribute your Thoughts:

0/2000 characters
Hildred
5 days ago
Agreed, it fits least privilege.
upvoted 0 times
...
Cordelia
10 days ago
I think User administrator is the best choice.
upvoted 0 times
...
Harrison
15 days ago
External Identity Provider administrator doesn't fit this scenario at all.
upvoted 0 times
...
Edda
20 days ago
Wait, can User1 really change the review frequency? Sounds odd.
upvoted 0 times
...
Kanisha
25 days ago
Definitely not the Privileged role administrator!
upvoted 0 times
...
Tricia
1 month ago
I think the Security administrator role could work too.
upvoted 0 times
...
Eun
1 month ago
User1 needs the User administrator role for that.
upvoted 0 times
...
Beckie
1 month ago
I recall that the External Identity Provider administrator role is more about managing external identities, so I don't think that's the answer.
upvoted 0 times
...
Veta
3 months ago
I’m a bit confused about the least privilege principle. Does that mean we should avoid roles like Privileged role administrator for this scenario?
upvoted 0 times
...
Ryan
3 months ago
This question feels similar to one we practiced where we had to assign roles based on specific permissions. I wonder if the Security administrator might be the right choice here.
upvoted 0 times
...
Ines
3 months ago
I think I remember that the User administrator role allows managing user settings, but I'm not sure if it covers modifying access packages.
upvoted 0 times
...

Save Cancel