Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 37 discussion

Actual exam question from Microsoft's AZ-104
Question #: 37
Topic #: 2
[All AZ-104 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant that contains three global administrators named Admin1, Admin2, and Admin3.
The tenant is associated to an Azure subscription. Access control for the subscription is configured as shown in the Access control exhibit. (Click the Access
Control tab.)

You sign in to the Azure portal as Admin1 and configure the tenant as shown in the Tenant exhibit. (Click the Tenant tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: No -
Only Admin3, the owner, can assign ownership.

Box 2: Yes -

Box 3: No -
Reference:
https://docs.microsoft.com/en-us/azure/cost-management-billing/manage/add-change-subscription-administrator

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
mlantonis
Highly Voted 3 years, 4 months ago
Correct Answer: Azure (RBAC) and Azure AD roles are independent. AD roles do not grant access to resources and Azure roles do not grant access to Azure AD. However, a Global Administrator in AD can elevate access to all subscriptions and will be User Access Administrator in Azure root scope. All 3 users are GA (AD) and Admin3 is owner of the subscription (RBAC). Admin1 has elevated access, so he is also User Access Admin (RBAC). To assign a user the owner role at the Subscription scope, you require permissions, such as User Access Admin or Owner. Box 1: Yes Admin1 has elevated access, so he is User Access Admin. This is valid. Box 2: Yes Admi3 is Owner of the Subscription. This is valid. Box 3: No Admin2 is just a GA in Azure AD scope. He doesn’t have permission in the Subscription.
upvoted 520 times
schvantz
2 years, 5 months ago
crystal clear
upvoted 5 times
...
Takloy
2 years, 11 months ago
Unless configure the elevated access for Admin 2 right? making admin2 user access administrator.
upvoted 2 times
...
kastanov
2 years, 2 months ago
Global Administrators can create resource groups in the subscription. How you work like this in your?
upvoted 1 times
...
franekfranek
2 years, 2 months ago
I'm not sure if Microsoft guys are aware of this elevated access to be honest lol
upvoted 5 times
Grande
2 years, 1 month ago
They surely know, and it was done for many reasons .As you must be a Global Admin to have the elevation ability. so its assume if you are a GA you are qualified
upvoted 1 times
...
...
...
ashish2201
Highly Voted 3 years, 4 months ago
Answer is correct, tested in Lab 1. No : Admin1 is a Global Administrator at Tenant which does not give it permission on subscription therefore cannot assign Owner Roles 2. Yes : Admin 3 is Global Administrator + Owner of Subscription therefore can assign Owner role to other user. 3. NO : Admin2 is Global Administrator for Tenant and do not have any rights on Subscription thereofore cannot create resources in it.
upvoted 59 times
ashish2201
3 years, 4 months ago
Kindly ignore my previous comment, below is the correct one 1. Yes : Admin1 is a Global Administrator at Tenant which does not give it permission on subscription but as per exibit it has taken control to manage access to all Azure subscriptions therefore it now has access to manage subscription therefore can assign role to other users. 2. Yes : Admin 3 is Global Administrator + Owner of Subscription therefore can assign Owner role to other user. 3. NO : Admin2 is Global Administrator for Tenant and do not have any rights on Subscription therefore cannot create resources in it.
upvoted 109 times
...
Praveen66
3 years, 1 month ago
Even if your a global administrator at the Tenant level you can grant the access of owner to any other user to in tenant for the subscription. Simple example is the default account through which you have registered is global admin, if you have created another user account you can very well assign a owner role to him for a sub
upvoted 2 times
...
...
james1890
Most Recent 2 weeks, 2 days ago
By default, Azure roles and Azure AD roles do not span Azure and Azure AD. However, if a Global Administrator elevates their access by choosing the Access management for Azure resources switch in the Azure portal, the Global Administrator will be granted the User Access Administrator role (an Azure role) on all subscriptions for a particular tenant. The User Access Administrator role enables the user to grant other users access to Azure resources. This switch can be helpful to regain access to a subscription. For more information, see Elevate access to manage all Azure subscriptions and management groups. Several Azure AD roles span Azure AD and Microsoft 365, such as the Global Administrator and User Administrator roles. For example, if you are a member of the Global Administrator role, you have global administrator capabilities in Azure AD and Microsoft 365, such as making changes to Microsoft Exchange and Microsoft SharePoint. However, by default, the Global Administrator doesn't have access to Azure resources. Box 1: YES Box 2: YES Box 3: NO
upvoted 2 times
...
Lazylinux
2 weeks, 2 days ago
Guys i was convinced NYN and only Bill Gates would have convinced me otherwise!!!!! until i read those two links below i than realized it is YYN for sure So answer is YYN Also as point admin2 can assigned themselves the user admin by click YES to the Access management for Azure resources Below is snippet but i encourage you read all When you set the toggle to Yes, you are assigned the User Access Administrator role in Azure RBAC at root scope (/). This grants you permission to assign roles in all Azure subscriptions and management groups associated with this Azure AD directory. This toggle is only available to users who are assigned the Global Administrator role in Azure AD. When you set the toggle to No, the User Access Administrator role in Azure RBAC is removed from your user account. You can no longer assign roles in all Azure subscriptions and management groups that are associated with this Azure AD directory. You can view and manage only the Azure subscriptions and management groups to which you have been granted access. will continue in reply as txt too large
upvoted 2 times
Lazylinux
2 years, 3 months ago
further info below Note: If you're using Privileged Identity Management, deactivating your role assignment does not change the Access management for Azure resources toggle to No. To maintain least privileged access, we recommend that you set this toggle to No before you deactivate your role assignment. Click Save to save your setting. This setting is not a global property and applies only to the currently signed in user. You can't elevate access for all members of the Global Administrator role. More info here: https://docs.microsoft.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin#how-does-elevated-access-work
upvoted 1 times
...
...
SeMo0o0o0o
1 month ago
wrong Yes Yes No
upvoted 2 times
...
Makoporosh
3 months ago
The answer is NYN: Global Administrators in Azure AD have the highest level of access in the Azure Active Directory, allowing them to manage users, groups, and other directory-related functions. However, this role does not automatically grant them access to manage Azure subscriptions and resources within those subscriptions.
upvoted 1 times
...
RanaYasirAleem
3 months, 3 weeks ago
Admin1 can add Admin 2 as an owner of the subscription. Yes: Admin1 is a global administrator, and based on the tenant settings, global administrators can manage access to all Azure subscriptions and management groups in this directory. Admin3 can add Admin 2 as an owner of the subscription. Yes: Admin3 is already assigned the "Owner" role for the subscription. An owner has full access, including the ability to assign roles to other users. Admin2 can create a resource group in the subscription. Yes: Admin2 is a global administrator. Global administrators have the highest level of permissions in Azure AD and can manage all aspects of the directory and subscription.
upvoted 2 times
...
SofiaLorean
4 months, 3 weeks ago
Answer should be : Yes Yes No
upvoted 2 times
...
3c5adce
4 months, 4 weeks ago
I believe the more recent and tested answer which is YYN
upvoted 2 times
...
3c5adce
4 months, 4 weeks ago
Answer is YYN
upvoted 2 times
...
Nateramj
6 months ago
My thought here is Box1:Admin1 even with Global admin permissions, User Administrator refers to the 365 admin console, and not Azure resources. They would need RBAC control to the subscription in the form of User Access Admin/Owner to add themselves to be able to add RBAC controls for others-NO is correct Box 2:Admin 3 is an Owner of the subscription, subsequently meaning the ability to add RBAC controls for other Admins-YES is the correct Answer Box 3: whilst Admin 2 is a GA they do not possess the correct RBAC role for the subscription resource meaning they cannot hand out permissions-Correct answer is NO
upvoted 1 times
...
_gio_
6 months, 2 weeks ago
YES YES NO Admin3 can elevate his permissions but in this question only Admin 1 has elevated his permissions
upvoted 1 times
...
tashakori
6 months, 3 weeks ago
No no no
upvoted 1 times
...
allyou
7 months, 3 weeks ago
I tested them in the lab, the answers are Y, Y, Y. the questions are somewhat nuanced, if I rephrase it like this: is the AdminX user capable/has the possibility of... It becomes obvious to answer with Y, Y, Y because Admin2 can elevate access like Admin1 to control the subscription. https://learn.microsoft.com/fr-fr/azure/role-based-access-control/elevate-access-global-admin
upvoted 1 times
...
Trs223333
10 months, 2 weeks ago
Yes, Yes, and No
upvoted 1 times
...
mihir25
10 months, 3 weeks ago
ANSWER IS YES YES NO VERIFIED AND DONE R&D DON'T WASTE MUCH TIME
upvoted 4 times
...
sjsaran
1 year ago
As same as Admin 1, why can't admin 2 take Access management for Azure resources, as admin 2 is also a global admin
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...