To create access reviews for Azure resources, you must be assigned to the Owner or the User Access Administrator role for the Azure resources. To create access reviews for Azure AD roles, you must be assigned to the Global Administrator or the Privileged Role Administrator role.
https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-create-roles-and-resource-roles-review#prerequisites
Global Administrator:
Can manage all aspects of Azure AD, including creating and managing access reviews for Azure AD roles.
Privileged Role Administrator:
Specifically responsible for managing role assignments in Azure AD and can create access reviews for privileged roles, including Azure AD roles like Global Administrator, Security Administrator, etc.
User Access Administrator (when managing resources):
If access reviews are tied to Azure resources, this role might be able to initiate reviews for roles assigned to those resources.
To create access reviews while adhering to the principle of least privilege, you would typically need a role with the minimum permissions necessary to initiate and manage access reviews, such as a "User Access Administrator" role in most identity management systems, allowing you to review user access without granting broader administrative privileges.
To create access reviews for Azure resources, you must be assigned to the Owner or the User Access Administrator role for the Azure resources. To create access reviews for Microsoft Entra roles, you must be assigned at least the Privileged Role Administrator role.
User administrators cannot create access reviews for Azure AD roles. The User administrator role is primarily responsible for managing user accounts, groups, and password resets, but it does not have the necessary permissions to manage access reviews or governance tasks related to Azure AD roles.
To create access reviews for Azure AD roles, roles like Identity Governance Administrator or Privileged Role Administrator are required. These roles have the necessary permissions for managing access reviews, especially related to Azure AD roles.
To allow User1 to create access reviews for Azure AD roles while adhering to the principle of least privilege, you should assign B. Identity Governance Administrator.
The Identity Governance Administrator role enables a user to manage access reviews, terms of use, and privileged access settings in Azure AD. This role is specifically suited for handling access reviews while limiting permissions to only governance-related tasks, aligning with the principle of least privilege.
To create access reviews for Azure resources, you must be assigned to the Owner or the (User Access Administrator) role for the Azure resources.
To create access reviews for Microsoft Entra roles, you must be assigned at least the (Privileged Role Administrator) role.
REF: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review#prerequisites
Correct Answer: A
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task
Least privileged roles by task in Microsoft Entra ID
Create, update, or delete access review of a group or of an app- User Administrator
"To create access reviews for Microsoft Entra roles, you must be assigned to the Global Administrator or the Privileged Role Administrator role."
https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review#prerequisites
Access reviews: User Administrator (with the exception of access reviews of Azure or Microsoft Entra roles, which require Privileged Role Administrator). In this case, the Access review is for an Azure role which requires Privileged Role Administrator.
https://learn.microsoft.com/en-us/entra/id-governance/identity-governance-overview?WT.mc_id=Portal-Microsoft_Azure_ELMAdmin#appendix---least-privileged-roles-for-managing-in-identity-governance-features
Look at the table here https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews
Specifically the row "Microsoft Entra roles"
The correct answer is B. Identity Governance Administrator.
The Identity Governance Administrator role allows users to create and manage access reviews for Azure AD roles, as well as other identity governance features.
Privileged role administrator: This role allows users to manage all privileged roles in Azure AD. This is more permission than User1 needs, as they only need to be able to create access reviews for Azure AD roles.
This is actually correct. If people are studying for this test they should know by now that if something is referencing Azure AD the test will Mean Azure Entra ID
https://learn.microsoft.com/en-us/entra/id-governance/create-access-review
I stand corrected -
To create access reviews for Azure resources, you must be assigned to the Owner or the User Access Administrator role for the Azure resources. To create access reviews for Microsoft Entra roles, you must be assigned to the Global Administrator or the Privileged Role Administrator role.
Citation:
https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-create-roles-and-resource-roles-review#prerequisites
In Microsoft 365 (M365), users with specific roles can create access reviews for Azure Active Directory (Azure AD) roles. Here are the roles that can perform this task:
Global Administrator: Global administrators have full access to all administrative features in Microsoft 365 and Azure AD, including the ability to create access reviews for Azure AD roles.
Security Administrator: Security administrators have permissions to manage security-related settings in Azure AD, and they can create access reviews for Azure AD roles.
Privileged Role Administrator: Privileged Role Administrators can manage assignments for privileged roles in Azure AD, including the ability to create access reviews for these roles.
The correct answer is B. Identity Governance Administrator.
According to the web search results, the Identity Governance Administrator role can create and manage access reviews for Azure AD roles1. The Privileged role administrator role can only manage Azure AD roles, but not access reviews2. The User administrator and User Access Administrator roles do not have permissions to create or manage access reviews3.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
kanag1
Highly Voted 1 year, 4 months agoniklas1242
Most Recent 22 hours, 45 minutes agoATimTimm
3 weeks, 3 days agoCybersecgirl
2 months, 1 week agoCybersecgirl
2 months, 1 week agohml_2024
2 months, 4 weeks agohml_2024
3 months agohml_2024
3 months agosrysgbvjumozmail
4 months, 1 week agoJuanZ
7 months, 3 weeks agoklayytech
7 months, 3 weeks agorazit
8 months, 3 weeks agoLeuxah
11 months, 1 week agohaazybanj
1 year agoNyamnyam
1 year, 1 month agohaazybanj
1 year, 1 month agothrowaway10188
10 months, 3 weeks agothrowaway10188
10 months, 2 weeks agoitismadu
1 year, 1 month agoitismadu
1 year, 1 month agoshuhaidawahab
1 year, 1 month ago