exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 2 question 21 discussion

Actual exam question from Microsoft's SC-300
Question #: 21
Topic #: 2
[All SC-300 Questions]

You have an Azure Active Directory (Azure AD) tenant that contains a user named SecAdmin1. SecAdmin1 is assigned the Security administrator role.
SecAdmin1 reports that she cannot reset passwords from the Azure AD Identity Protection portal.
You need to ensure that SecAdmin1 can manage passwords and invalidate sessions on behalf of non-administrative users. The solution must use the principle of least privilege.
Which role should you assign to SecAdmin1?

  • A. Authentication administrator
  • B. Helpdesk administrator
  • C. Privileged authentication administrator
  • D. Security operator
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sezza_blunt
Highly Voted 3 years, 10 months ago
Answer must be B - Helpdesk Administrators. From the docs: Authentication administrator: can reset passwords for non-admins but can't invalidate sessions. https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#authentication-administrator Helpdesk administrator: Users with this role can change passwords, invalidate refresh tokens, manage service requests, and monitor service health. Invalidating a refresh token forces the user to sign in again. https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#helpdesk-administrator Privileged Authentication Administrator: can reset all passwords (admins & non-admins) but can't invalidate any sessions. https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#privileged-authentication-administrator Security Operator: can't reset any passwords. https://docs.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#security-operator
upvoted 79 times
Alcpt
1 year ago
The Helpdesk admin does NO invalidate sessions capability.
upvoted 1 times
...
[Removed]
3 years, 2 months ago
I think it's B too. Helpdesk Administrator seems to be the correct answer.
upvoted 4 times
...
Domza
3 years, 10 months ago
There you go - Help Desk Admin - "Users with this role can change passwords, invalidate refresh tokens"
upvoted 5 times
...
Jhill777
2 years, 5 months ago
Authenication Administrator Role Permmissions includes: microsoft.directory/users/invalidateAllRefreshTokens Force sign-out by invalidating user refresh tokens.
upvoted 7 times
...
...
rozgonyi
Highly Voted 3 years, 12 months ago
Tl;dr: A In details: Privileged Auth Admin can reset passwords of non admins and admin accounts Helpdesk Admins can reset non admins and Helpdesk Admins password Authentication Administrator can only reset non admin accounts password To follow the least privilege requirement, Authentication Administrator should be the answer
upvoted 65 times
Acbrownit
3 years ago
Definitely A - For non-admin users, permissions needed are Reset Passwords for Non-Admins and Invalidate Refresh Tokens. Both exist in Authentication Administrator role. Privileged would allow access to Admin users.
upvoted 3 times
...
med4
3 years, 6 months ago
not sure why this answer is top voted - auth admin can manage MFA settings which high prev - help desk admin can just manage passwords and invalided them ( invalided refresh token)
upvoted 26 times
Holii
1 year, 10 months ago
Agreed. Helpdesk Administrator can do explicitly what the question asks. Authentication Administrator has additional sensitive controls, such as revoking MFA or forcing users to re-register against non-password authentication methods (FIDO/MFA)
upvoted 3 times
...
...
...
anonymousarpanch
Most Recent 2 months, 3 weeks ago
Selected Answer: B
both helpdesk administrator and authentication administrator can do similiar tasks asked here. the least privileged is helpdesk administrator as the authentication administrator can also modify authenticaiton related settings which is what a helpdesk administrator cannot do
upvoted 1 times
...
Sunth65
4 months ago
Selected Answer: A
A. Authentication administrator is the correct answer. Authentication Administrator can only reset non admin accounts password
upvoted 1 times
...
Nail
6 months, 1 week ago
Selected Answer: A
Authentication Administrator and Helpdesk Administrator both have microsoft.directory/users/invalidateAllRefreshTokens and microsoft.directory/users/password/update permissions so I really feel like it comes down to the "non-admin" part of the question. Helpdesk Administrators have more permissions than they need in this area, i.e., they can reset passwords of admins. Authentication Administrators can only reset the passwords of non-admins so the answer is Authentication Administrators.
upvoted 1 times
...
ItzVerified
1 year ago
Selected Answer: B
Help Desk Admin - "Users with this role can change passwords, invalidate refresh tokens"
upvoted 1 times
...
NICKTON81
1 year ago
Selected Answer: B
B https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#helpdesk-administrator
upvoted 1 times
...
Bhavneet1802
1 year, 2 months ago
Selected Answer: B
Users with this role can change passwords, invalidate refresh tokens, manage service requests, and monitor service health. Invalidating a refresh token forces the user to sign in again.
upvoted 2 times
...
JanioHSilva
1 year, 4 months ago
Selected Answer: B
Based on this, it seems that the Authentication Administrator role would be the most suitable, as it allows you to reset passwords for non-administrators. However, the ability to invalidate sessions is also required, and the Authentication Administrator role does not provide this. The Helpdesk Administrator role, on the other hand, allows both password reset and session invalidation for non-administrators, which satisfies both requirements for SecAdmin1.
upvoted 3 times
...
Nyamnyam
1 year, 5 months ago
Selected Answer: B
"manage passwords"-term has only one match by Password Administrator, and the referenced action is microsoft.directory/users/password/update, which is to "Reset the password". This action is assigned to Helpdesk Administrator as well. On the other side, Password Administrator cannot "invalidate sessions". Hmm, this term has no matches, but "invalidate" points to microsoft.directory/users/invalidateAllRefreshTokens, which is the correct action we look for. And guess what - this action is assigned to Helpdesk Administrator again.
upvoted 3 times
...
haazybanj
1 year, 5 months ago
Selected Answer: B
The best answer is B. Helpdesk administrator. The Helpdesk administrator role allows users to reset passwords, invalidate refresh tokens, manage service requests, and monitor service health. This role is a good choice for SecAdmin1 because it allows her to manage passwords and invalidate sessions on behalf of non-administrative users, without giving her the full permissions of a Security administrator.
upvoted 3 times
...
haazybanj
1 year, 5 months ago
Selected Answer: C
The answer is: B. Helpdesk administrator The Helpdesk administrator role allows users to reset passwords and invalidate sessions on behalf of non-administrative users. It also allows users to manage authentication methods and multi-factor authentication settings for non-administrative users.
upvoted 1 times
haazybanj
1 year, 5 months ago
The best answer is B. Helpdesk administrator. The Helpdesk administrator role allows users to reset passwords, invalidate refresh tokens, manage service requests, and monitor service health. This role is a good choice for SecAdmin1 because it allows her to manage passwords and invalidate sessions on behalf of non-administrative users, without giving her the full permissions of a Security administrator.
upvoted 2 times
...
...
Nivos23
1 year, 5 months ago
Selected Answer: B
I think it's B
upvoted 2 times
...
sherifhamed
1 year, 7 months ago
Selected Answer: B
In Azure AD, the principle of least privilege is essential for security. To ensure that SecAdmin1 can manage passwords and invalidate sessions for non-administrative users without granting excessive permissions, you should assign the B: "Helpdesk administrator" role. Assigning the "Authentication administrator" or "Privileged authentication administrator" roles might provide more privileges than necessary for SecAdmin1's requirements.
upvoted 1 times
...
dule27
1 year, 9 months ago
Selected Answer: A
A. Authentication administrator
upvoted 1 times
...
Sango
1 year, 9 months ago
A. The key here is non-admin accounts. Only the Auth Admin meets the criteria. Auth Admin: Can access to view, set and reset authentication method information for any non-admin user. Helpdesk Admin: Can reset passwords for non-administrators and Helpdesk Administrators. Priv Admin:Can access to view, set and reset authentication method information for any user (admin or non-admin). Security Operator: Creates and manages security events.
upvoted 3 times
...
Garito
1 year, 10 months ago
Selected Answer: B
Answered correctly in similar question.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago