exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 4 question 50 discussion

Actual exam question from Microsoft's SC-300
Question #: 50
Topic #: 4
[All SC-300 Questions]

You have an Azure AD tenant that contains an access package named Package1 and a user named User1. Package1 is configured as shown in the following exhibit.



You need to ensure that User1 can modify the review frequency of Package1. The solution must use the principle of least privilege.

Which role should you assign to User1?

  • A. Security administrator
  • B. Privileged role administrator
  • C. External Identity Provider administrator
  • D. User administrator
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
penatuna
Highly Voted 1 year, 7 months ago
Selected Answer: D
Tried this with all the suggested answer, and none of them can modify the review frequency of Package1. See explanation below. Security Admin - Cannot update Policy Privileged role administrator - Gets “No access” to Access Packages. External Identity Provider administrator - Gets “No access” to Access Packages. User administrator - Gets “No access” to Access Packages. User administrator used to be the right choice for this question. However, things have now changed: The User Administrator role is no longer allowed to manage catalogs and access packages in Azure AD Entitlement Management. Please transition to the Identity Governance Administrator role to continue managing access without disruption, or go to the Entitlement Management settings page if you need to temporarily opt out. So, if there is an option in this question to choose Identity Governance Administrator, choose that. https://learn.microsoft.com/azure/active-directory/governance/identity-governance-overview?WT.mc_id=Portal-Microsoft_Azure_ELMAdmin#appendix---least-privileged-roles-for-managing-in-identity-governance-features
upvoted 25 times
Frank9020
3 months ago
To ensure that User1 can modify the review frequency of Package1 while adhering to the principle of least privilege, you should assign the Privileged Role Administrator role (option B). This role provides the necessary permissions to manage access reviews and related tasks, including modifying review frequencies.
upvoted 1 times
...
ducle97
1 year, 3 months ago
Agree!
upvoted 2 times
...
...
Leacco99
Highly Voted 1 year, 7 months ago
Should be Identity Governance Admin if up to date, but if not present, choose User Administrator. "The least privileged role for Entitlement management has changed from the User Administrator role to the Identity Governance Administrator role." https://learn.microsoft.com/en-us/azure/active-directory/governance/identity-governance-overview?WT.mc_id=Portal-Microsoft_Azure_ELMAdmin#appendix---least-privileged-roles-for-managing-in-identity-governance-features
upvoted 8 times
...
dvmhike
Most Recent 5 months, 2 weeks ago
To ensure that User1 can modify the review frequency of Package1 while adhering to the principle of least privilege, you should assign the Privileged role administrator role to User1. This role allows the user to manage role assignments in Azure AD, including modifying access packages and their review settings.
upvoted 1 times
...
Labelfree
5 months, 2 weeks ago
I haven't seen anyone say "Privileged role administrator" yet if you ask which role can update or modify Access Reviews in Entra, ChatGPT, Copilot and Google all suggest Privileged role administrator. is that not correct?
upvoted 1 times
...
martutene
6 months, 2 weeks ago
Create and manage access reviews (creators) Access package Global Administrator Identity Governance Administrator Catalog owner (for the access package) Access package manager (for the access package) https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews
upvoted 1 times
...
hml_2024
7 months, 3 weeks ago
Selected Answer: B
To ensure that User1 can modify the review frequency of Package1 while adhering to the principle of least privilege, the appropriate role would be B. Privileged role administrator. The Privileged Role Administrator role allows users to manage role assignments in Azure AD and manage access packages, which includes modifying access reviews and their configurations. This provides the necessary permissions without granting excessive access.
upvoted 2 times
...
a6792d4
11 months, 1 week ago
The least privileged role for Entitlement management has changed from the User Administrator role to the Identity Governance Administrator role.
upvoted 2 times
...
klayytech
1 year ago
Selected Answer: B
Create and manage access reviews for Access package Global administrator Identity Governance administrator Catalog owner (for the access package) Access package manager (for the access package)
upvoted 3 times
...
Sorrynotsorry
1 year, 5 months ago
Selected Answer: B
To create access reviews for Azure resources, you must be assigned to the Owner or the User Access Administrator role for the Azure resources. To create access reviews for Microsoft Entra roles, you must be assigned to the Global Administrator or the Privileged Role Administrator role.
upvoted 2 times
...
kanag1
1 year, 8 months ago
Selected Answer: D
o enable reviews of access packages, you must meet the prerequisites for creating an access package: Microsoft Azure AD Premium P2 or Microsoft Entra ID Governance Global administrator, Identity Governance administrator, User administrator, Catalog owner, or Access package manager
upvoted 4 times
JimboJones99
1 year, 6 months ago
This has been superseded. See penatuna and Leacco99's comments above.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago