exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 124 discussion

Actual exam question from Microsoft's MS-102
Question #: 124
Topic #: 1
[All MS-102 Questions]

HOTSPOT
-

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.



You are implementing Microsoft Defender for Endpoint.

You need to enable role-based access control (RBAC) to restrict access to the Microsoft 365 Defender portal.

Which users can enable RBAC, and which users will no longer have access to the Microsoft 365 Defender portal after RBAC is enabled? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cb0900
Highly Voted 1 year, 7 months ago
Agree with the answers. Enable RBAC: Admin1 and Admin 2 No longer have access: Admin 3 and Admin 4 Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Azure AD Security reader role) to lose access until they are assigned to a role. https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide#before-you-begin https://www.examtopics.com/discussions/microsoft/view/110910-exam-ms-101-topic-2-question-138-discussion/
upvoted 18 times
imlearningstuffagain
1 year, 5 months ago
this is nice wording, the Application Administrator didn't have access to begin with. So he/she doesn't lose access. Correct?
upvoted 8 times
nils241
1 year, 3 months ago
Users with "Application Administor Role" can only create and manage all aspects of enterprise applications, application registrations, and application proxy settings.
upvoted 2 times
...
...
sergioandreslq
1 year, 5 months ago
Initially, only those with Microsoft Entra Global Administrator or Security Administrator rights will be able to create and assign roles in the Microsoft 365 Defender portal https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide#before-you-begin
upvoted 1 times
...
...
Frank_2022
Most Recent 3 days, 13 hours ago
Users who can enable RBAC: Admin1 (Global Admin) Admin2 (Security Admin) Users who will lose access after RBAC is enabled: Admin3 (Security Operator) Admin4 (Security Reader) Admin5 (Application Admin)
upvoted 1 times
...
APK1
8 months ago
Given answer is correct. For the second question here is the key point in the question "Users that will NO LONGER have access" - The Application Admin never had access so shouldn't be included.
upvoted 1 times
...
jarattdavis
8 months ago
= Admin1 and Admin2 can enable RBAC because they have the highest-level administrative privileges (Global Administrator and Security Administrator). = Admin3, Admin4, and Admin5 will lose access to the Microsoft 365 Defender portal after RBAC is enabled. This is because they have roles that are typically granted limited or read-only access, and RBAC allows for granular control over permissions.
upvoted 1 times
...
Murad01
9 months, 3 weeks ago
Given answer are correct
upvoted 1 times
...
Jamesat
11 months, 3 weeks ago
Agreed. After enabling RBAC only Global Admin and Security Admin will have access so Admin 1 and Admin 2 is correct. For the second question it is Admin 3 and Admin 4. The question is Users that will NO LONGER have access. The Application Admin never had access so shouldn't be included.
upvoted 1 times
...
Tomtom11
1 year, 1 month ago
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide Initially, only those with Microsoft Entra Global Administrator or Security Administrator rights will be able to create and assign roles in the Microsoft Defender portal, therefore, having the right groups ready in Microsoft Entra ID is important. Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Microsoft Entra Security reader role) to lose access until they are assigned to a role. Users with admin permissions are automatically assigned the default built-in Defender for Endpoint global administrator role with full permissions. After opting in to use RBAC, you can assign additional users that are not Microsoft Entra Global or Security Administrators to the Defender for Endpoint global administrator role. After opting in to use RBAC, you cannot revert to the initial roles as when you first logged into the portal.
upvoted 1 times
...
m2L
1 year, 3 months ago
NO2 : Admin3, Admin4, Admin5
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago