An organization wants to delegate management of Self-Service Password Reset (SSPR) and external collaboration configurations to different administrators using the principle of least privilege.
Which minimum administrative roles must be assigned to perform each of the specified directory and external identity configuration scenarios?
- Configure federation with Google or Facebook as external identity providers for B2B collaboration.External Identity Provider Administrator
- Invite external guest users to the tenant when guest invitations are restricted to administrative roles in external collaboration settings.Guest Inviter
- Configure tenant-wide Self-Service Password Reset (SSPR) authentication methods and registration policies.Authentication Policy Administrator
- Reset the password of a user who is assigned the Helpdesk Administrator role.User Administrator
Answer
Configure federation with Google or Facebook maps to External Identity Provider Administrator; Invite external guest users maps to Guest Inviter; Configure tenant-wide SSPR settings maps to Authentication Policy Administrator; Reset the password of a Helpdesk Administrator maps to User Administrator.
The correct matches pair each directory administration task with its minimum required role based on the principle of least privilege. External Identity Provider Administrator manages federation, Guest Inviter permits B2B invitations under restrictions, Authentication Policy Administrator manages SSPR methods, and User Administrator handles password resets for Helpdesk Administrators.
Step-by-Step Solution
Key Concept
Delegating administrative permissions using least privilege for Microsoft Entra ID Self-Service Password Reset (SSPR) and external collaboration settings.