exam questions

Exam SC-300 All Questions

View all questions & answers for the SC-300 exam

Exam SC-300 topic 1 question 34 discussion

Actual exam question from Microsoft's SC-300
Question #: 34
Topic #: 1
[All SC-300 Questions]

DRAG DROP
-

You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.

You need to ensure that User1 can create access reviews for groups, and that User2 can review the history report for all the completed access reviews. The solution must use the principle of least privilege.

Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Halwagy
Highly Voted 2 years, 1 month ago
User 1 : User Administrator User 2 : Security Reader
upvoted 58 times
klayytech
10 months, 3 weeks ago
https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews Global Admin Global Reader security reader does not have permission to read the history for Azure resource roles
upvoted 4 times
...
klayytech
11 months, 2 weeks ago
Read access review of a group or of an app Least privileged role = Security Reader Additional roles= Security Administrator User Administrator https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task#enterprise-applications
upvoted 5 times
HaubeRR89
3 months ago
User 1 : User Administrator User 2 : Global Reader Global Administrator, Identity Governance Administrator, and Global Reader can see history reports for all access reviews. All other users are only allowed to see reports on access reviews that they generate. https://learn.microsoft.com/en-us/entra/id-governance/access-reviews-downloadable-review-history
upvoted 3 times
...
...
oscarpopi
2 years, 1 month ago
Correct
upvoted 3 times
...
...
doch
Highly Voted 2 years, 1 month ago
User Admin Security Reader Ref: https://learn.microsoft.com/en-us/azure/active-directory/roles/delegate-by-task
upvoted 27 times
oscarpopi
2 years, 1 month ago
Correct, that's a nice article, I'll bookmark it
upvoted 3 times
...
...
Bojana
Most Recent 3 days, 10 hours ago
User 1: User Administrator User 2: Report Reader To achieve this while adhering to the principle of least privilege, you can assign the following roles to User1 and User2: User1: Assign the User Administrator role. This role allows User1 to create access reviews for groups. User2: Assign the Reports Reader role. This role allows User2 to review the history report for all completed access reviews. By assigning these specific roles, you ensure that each user has only the permissions necessary to perform their tasks, adhering to the principle of least privilege.
upvoted 1 times
...
krutesh
3 weeks, 1 day ago
User1: User Administrator User2: Reports Reader The least privileged role that can create access reviews for groups in Azure Active Directory (Azure AD) is the “User Administrator” role. This role provides the necessary permissions to manage users and groups, including creating access reviews. The least privileged role that can review the history report for all completed access reviews in Azure Active Directory (Azure AD) is the “Report Reader” role. This role allows users to view various reports, including access review history reports, without granting them broader administrative permissions.
upvoted 2 times
...
Frank9020
2 months, 4 weeks ago
User1: User administrator: Allows managing users, groups, and access reviews, but does not provide global admin rights. User2: Reports reader: Allows access to reports and analytics without administrative permissions, aligning with least privilege.
upvoted 2 times
...
ColdCut
4 months, 1 week ago
The correct answer is: User1: User administrator User2: Global reader Explanation: User1 needs to create access reviews for groups. To create access reviews, the User administrator role is appropriate. The User administrator can manage user settings, including group memberships and access reviews. User2 needs to review the history report for all completed access reviews. The Global reader role allows users to view reports and other information across Microsoft 365 without granting them permissions to make any changes. This role aligns with the requirement for reviewing access review history, as it provides read-only access. Resource Links: For more details about roles and permissions: User Administrator role Global Reader role
upvoted 1 times
...
AlexBrazil
4 months, 2 weeks ago
According to https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task, User1: User Administrator "Create, update, or delete access review of a group or of an app" User2: Security Reader "Read access review of a Microsoft Entra role"
upvoted 2 times
...
BRZSZCL
4 months, 3 weeks ago
To ensure the least privilege principle is followed for each user: User1 needs to create access reviews for groups. The appropriate role for this task is User Access Administrator because it allows users to create and manage access reviews in Azure AD. User2 needs to review the history report for all completed access reviews. The role required for this is Reports Reader, which allows viewing reports without granting the ability to create or manage the reviews themselves. Summary: User1: User Access Administrator User2: Reports Reader
upvoted 4 times
...
hml_2024
5 months, 4 weeks ago
To meet the requirements while adhering to the principle of least privilege, you should assign the following roles: - **User1**: Assign the **User Administrator** role. This role allows User1 to create access reviews for groups¹. - **User2**: Assign the **Global Reader** role. This role allows User2 to review the history report for all completed access reviews without granting any additional administrative permissions².
upvoted 1 times
...
cluocal
6 months, 1 week ago
User1: User Admin (Create, update, or delete access review of a group or of an app) User 2: Security Reader (Read access review of a group or of an app) https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task
upvoted 3 times
...
srysgbvjumozmail
7 months, 1 week ago
User 1 : User Administrator User 2 : Security Reader https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews
upvoted 2 times
...
klayytech
10 months, 3 weeks ago
https://learn.microsoft.com/en-us/entra/id-governance/deploy-access-reviews#who-will-create-and-manage-access-reviews Global Admin Global Reader security reader does not have permission to read the history for Azure resource roles
upvoted 1 times
Discuss4certi
8 months, 2 weeks ago
Neither can a global reader. You need to be assigned the permissions for that resource. Therefore since it's not stated go for user admin for the creation of access review and security reader for the reports.
upvoted 1 times
...
...
ItzVerified
11 months ago
User 1 : User Administrator User 2 : Security Reader
upvoted 3 times
...
jtlucas99
11 months ago
Per Copilot: In Azure Active Directory (Azure AD), you can assign different roles to users to manage access reviews. For User1, you should assign the Access Review Contributor role. This role allows the user to create and manage access reviews, but it doesn’t allow them to make decisions on behalf of reviewers. For User2, you should assign the Access Review Reader role. This role allows the user to read access reviews and their decisions, but they can’t create, update, or delete access reviews. These roles follow the principle of least privilege, granting only the necessary permissions to each user for their specific tasks.
upvoted 1 times
...
klayytech
11 months, 2 weeks ago
Read access review of a group or of an app Least privileged role = Security Reader Additional roles= Security Administrator User Administrator https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task#enterprise-applications
upvoted 2 times
...
emartiy
11 months, 3 weeks ago
User1: User Admin User 2: security Reader
upvoted 2 times
...
RahulX
1 year, 1 month ago
Create, update, or delete access review of a group or of an app (User Administrator) Read access review of a group or of an app (Security Reader). https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/delegate-by-task
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago