Your company has a Microsoft Entra ID tenant that contains the following resources:
- An Administrative Unit named Sales-AU
- A security group named Sales-Group
- A user named User1 who is in Sales-AU and is a member of Sales-Group
- A user named Admin1 who is assigned the User Administrator role scoped to Sales-AU
You configure group-based licensing for Sales-Group. A Microsoft 365 E5 license is assigned to Sales-Group.
You discover that User1 is not assigned the license due to an empty usage location property.
You need to ensure that User1 is assigned the license. The solution must use the principle of least privilege.
What should you do?
- Have Admin1 configure the Usage location property on the user account of User1.Cevap
- BConfigure a dynamic membership rule for Sales-Group that automatically assigns the usage location attribute to its members.
- CAssign the User Access Administrator Azure RBAC role to Admin1, and then have Admin1 configure the Usage location property on the user account of User1.
- DAssign the Contributor Azure RBAC role for the Sales-AU scope to Admin1, and then have Admin1 configure the Usage location property on the user account of User1.
Cevap
Have Admin1 configure the Usage location property on the user account of User1.
The correct action is to have Admin1 configure the Usage location property on the user account of User1. In Microsoft Entra ID, group-based licensing requires each user to have a usage location configured on their individual user object before a license can be assigned. Admin1 holds the User Administrator role scoped to Sales-AU, and since User1 is a member of Sales-AU, Admin1 has the necessary administrative permissions to update User1's properties without requiring tenant-wide administrator roles.
Adım Adım Çözüm
Anahtar Kavram
Delegating administration of user properties and licenses using Administrative Units and scoped directory roles.
Tahmini Süre:1m 30s