An administrator manages a Microsoft Entra ID tenant that contains an administrative unit named Sales-AU. A dynamic user group named Sales-Dynamic-Group is a member of Sales-AU. A user named Admin1 is assigned the Groups Administrator role scoped to the Sales-AU administrative unit. Admin1 attempts to modify the query of the dynamic membership rule for Sales-Dynamic-Group. What is the outcome of Admin1's attempt to modify the rule?
- AThe update will succeed because the Groups Administrator role scoped to the administrative unit provides full management capabilities for all groups within that administrative unit.
- BThe operation will fail because modifying dynamic rules requires a subscription-level Azure RBAC role such as Owner or Contributor.
- The update will fail because dynamic membership rules can only be modified by administrators with group management roles assigned at the tenant scope.Answer
- DThe update will fail because only users with the User Administrator role scoped to the administrative unit are permitted to manage dynamic user group rules.
Answer
The update will fail because dynamic membership rules can only be modified by administrators with group management roles assigned at the tenant scope.
The correct option states that the update will fail because dynamic membership rules can only be modified by administrators with group management roles assigned at the tenant scope. In Microsoft Entra ID, administrative unit scope delegation does not extend to managing dynamic groups, even if the dynamic groups are members of the administrative unit. Dynamic group membership rules require tenant-wide privileges to modify.
Step-by-Step Solution
Key Concept
Delegating group management with administrative units and directory roles
Estimated Time:2m 0s