An organization has a Microsoft Entra ID tenant. The tenant contains a user named Admin1, a security group named Europe-Sales that has 50 member users, and an administrative unit named Europe-AU. Europe-AU contains the Europe-Sales group as its only member.
You assign the User Administrator role to Admin1 with Europe-AU as the scope.
Which action is Admin1 permitted to perform?
- Add new members to the Europe-Sales groupAnswer
- BReset the passwords of the users who are members of the Europe-Sales group
- CAssign the Virtual Machine Contributor role to the Europe-Sales group for an Azure resource group
- DConfigure a dynamic membership rule for the Europe-Sales group based on user attributes
Answer
Add new members to the Europe-Sales group
An administrator assigned the User Administrator role at the Administrative Unit (AU) scope can manage the properties and membership of groups that are direct members of the AU. Since Europe-Sales is a member of Europe-AU, Admin1 can add or remove members from it.
Step-by-Step Solution
Key Concept
Administrative Unit scoping and the non-transitive nature of group memberships in Microsoft Entra ID
Estimated Time:1m 30s