You are planning to delegate user management tasks in a Microsoft Entra ID tenant. You need to create a new group named Identity-Managers and assign the User Administrator role directly to this group. Which configuration is required for the Identity-Managers group?
- AThe group membership type must be set to Dynamic User with a rule that automatically includes users whose job title is Helpdesk Specialist.
- The group membership type must be set to Assigned, and the option to assign Microsoft Entra roles must be enabled during group creation.Cevap
- CThe group can be created with standard settings, and the User Administrator role must be assigned using Azure RBAC at the resource group scope.
- DThe group must be added to an Administrative Unit, which automatically elevates all members of the group to the User Administrator role at the tenant level.
Cevap
The group membership type must be set to Assigned, and the option to assign Microsoft Entra roles must be enabled during group creation.
The correct option is correct because assigning a Microsoft Entra ID role to a group requires creating a role-assignable group. This type of group must have the role-assignable property enabled during creation and only supports the 'Assigned' membership type to guarantee administrative oversight over the group's members.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra ID role-assignable groups require the 'Assigned' membership type and must have the role assignment setting enabled at the time of creation.