Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AZ-104 All Questions

View all questions & answers for the AZ-104 exam

Exam AZ-104 topic 2 question 50 discussion

Actual exam question from Microsoft's AZ-104
Question #: 50
Topic #: 2
[All AZ-104 Questions]

You have three offices and an Azure subscription that contains an Azure Active Directory (Azure AD) tenant.
You need to grant user management permissions to a local administrator in each office.
What should you use?

  • A. Azure AD roles
  • B. administrative units
  • C. access packages in Azure AD entitlement management
  • D. Azure roles
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
HananS
Highly Voted 2 years, 10 months ago
The answer is correct Administrative units restrict permissions in a role to any portion of your organization that you define. You could, for example, use administrative units to delegate the Helpdesk Administrator role to regional support specialists, so they can manage users only in the region that they support.
upvoted 46 times
magichappens
2 years, 6 months ago
Although I agree with your explanation the question is not really stating that administrative units are required as there is no statement about the local office administrators and weather they need to administer all users or should only administer the users of their respective office.
upvoted 15 times
...
...
NaoVaz
Highly Voted 2 years ago
Selected Answer: B
B) "administrative units" "It can be useful to restrict administrative scope by using administrative units in organizations that are made up of independent divisions of any kind."- https://docs.microsoft.com/en-us/azure/active-directory/roles/administrative-units#deployment-scenario
upvoted 16 times
...
SeMo0o0o0o
Most Recent 1 month ago
Selected Answer: B
B is corerct
upvoted 1 times
...
JananiToo
7 months, 2 weeks ago
Why some YouTube videos say azure AD roles?
upvoted 2 times
af68218
6 months, 2 weeks ago
The wording of the question, "what should you choose," is equivalent to "what is the best answer?" AD roles would work, but they wouldn't be the best answer, given that the question mentions having local administrators, which could be grouped together for practicality. The youtube video, like me, probably missed that.
upvoted 2 times
...
...
Amir1909
7 months, 3 weeks ago
B is correct
upvoted 1 times
...
Rednevi
1 year ago
Selected Answer: B
B. Administrative units Administrative units in Azure AD allow you to organize and delegate administrative tasks to specific administrative units. You can assign specific permissions and roles to administrators based on these units. This approach allows local administrators to have control over users and resources within their respective offices without having full global permissions. It's a more granular and decentralized approach to user management. Azure AD roles (Option A) typically deal with assigning permissions at a broader level, and they might not provide the necessary granularity for managing users within specific offices. Access packages in Azure AD entitlement management (Option C) are used for granting access to resources and applications rather than delegating user management tasks. Azure roles (Option D) are primarily focused on managing permissions for Azure resources and services, not user management within Azure AD. So, the most suitable choice for delegating user management permissions to local administrators in different offices is "B. Administrative units."
upvoted 6 times
...
grimrodd
1 year, 1 month ago
Selected Answer: A
I think A because, the question does not state that each local administrator should be restricted to only administer the users in their office, so assigning the role 'User Administrator' would be the solution to this question would it not?
upvoted 3 times
urbanmonk
1 year ago
Do not overthink these questions. The phrase "... Local administrator in each office" gave the answer away for Administrative Unit.
upvoted 3 times
...
...
kamalpur
1 year, 2 months ago
answer is correct https://youtu.be/XNqSQOYtcPQ
upvoted 1 times
...
Chris76
1 year, 5 months ago
Selected Answer: B
"You need to grant user management permissions to a local administrator in each office" vs "You need to grant *LOCAL* user management permissions to a local administrator in each office" IMHO the latter is a stronger case for Administrative Units. But the mere fact of mentioning "Local administrator in each office", implies an already in place setup of Administrative Units. Location/Division - based admin is use case for Administrative Units.
upvoted 4 times
...
lokii9980
1 year, 6 months ago
B. Administrative units would be the best option to grant user management permissions to a local administrator in each office. Administrative units are a feature in Azure AD that allow you to delegate administrative privileges to specific groups of users or administrators. By creating an administrative unit for each office, you can grant the local administrator in each office the necessary permissions to manage users and groups within their own office, without giving them access to the entire Azure AD tenant. Azure AD roles and Azure roles are used to grant permissions to perform specific tasks within Azure services, but they are not specifically designed for user management within Azure AD. Access packages in Azure AD entitlement management are used to manage access to specific resources and applications within an organization, but they are not specifically designed for delegating administrative privileges.
upvoted 3 times
...
Mazinger
1 year, 7 months ago
Selected Answer: B
To grant user management permissions to a local administrator in each office, you should use Azure AD administrative units. Administrative units are a feature in Azure AD that allow you to delegate administrative permissions to specific groups of users or administrators. You can create an administrative unit for each office and then assign a local administrator to manage the users and groups within that unit. Azure AD roles, Azure roles, and access packages in Azure AD entitlement management are also used to grant permissions to users and groups, but they are not designed specifically for delegating administrative permissions to specific groups of users or administrators based on their location or organizational structure. Therefore, they are not the best option for granting user management permissions to local administrators in each office. So, the correct answer is B. administrative units.
upvoted 5 times
allyQ
1 year, 7 months ago
True, But the scenario says: You need to grant user management permissions to a local administrator in each office. Not.... You need to grant 'local'user management permissions to a local administrator in each office. The answer assumes a scope that the question does nt actually specify.
upvoted 5 times
Chris76
1 year, 5 months ago
Finally somebody sane with attention to details
upvoted 2 times
...
...
...
zellck
1 year, 8 months ago
Selected Answer: B
B is the answer. https://learn.microsoft.com/en-us/azure/active-directory/roles/administrative-units An administrative unit is an Azure AD resource that can be a container for other Azure AD resources. An administrative unit can contain only users, groups, or devices. Administrative units restrict permissions in a role to any portion of your organization that you define. You could, for example, use administrative units to delegate the Helpdesk Administrator role to regional support specialists, so they can manage users only in the region that they support.
upvoted 3 times
...
brein33
1 year, 8 months ago
Administrative units is correct
upvoted 1 times
...
EmnCours
2 years, 1 month ago
Selected Answer: B
Correct Answer: B 🗳️ Reference: https://docs.microsoft.com/en-us/azure/active-directory/roles/administrative-units
upvoted 3 times
...
Azure_daemon
2 years, 7 months ago
It's very obvious, Administrative Unit is the answer
upvoted 2 times
...
edengoforit
2 years, 7 months ago
Answer is Administrative unit If you go to porta.azure.com -> Azure Active Directory -> Roles and Administrators from the left pane, you will be able to see multiple built in role called 'User Administrator'. If you click that role, you are able to assign, update or delete the user to the role
upvoted 3 times
...
Snownoodles
2 years, 9 months ago
Why is A not correct? Even with B(admin unit), you have to assign AAD role to administrators for an admin unit.
upvoted 5 times
Mozbius_
2 years, 8 months ago
I think that B is the answer because it is what the question is implying a scenario for which "Administrative Units" are specifically tailored for... "Deployment scenario It can be useful to restrict administrative scope by using administrative units in organizations that are made up of independent divisions of any kind." https://docs.microsoft.com/en-us/azure/active-directory/roles/administrative-units#:~:text=An%20administrative%20unit%20is%20an%20Azure%20AD%20resource,any%20portion%20of%20your%20organization%20that%20you%20define.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...