You manage a Microsoft Entra ID tenant. You create an administrative unit named Regional-AU and add several security groups to it.
You need to delegate the ability to manage the membership of these security groups to a user named Admin1. The solution must follow the principle of least privilege.
Which role and scope should you assign to Admin1?
- AGroups Administrator role scoped to an Azure resource group
- BUser Administrator role scoped to Regional-AU
- Groups Administrator role scoped to Regional-AUCevap
- DContributor role scoped to the Azure subscription
Cevap
Groups Administrator role scoped to Regional-AU
Assigning the Groups Administrator role scoped to Regional-AU is correct because it grants the specific permissions needed to manage group memberships, and administrative units allow directory role delegation to be scoped to a subset of directory objects, satisfying the principle of least privilege.
Adım Adım Çözüm
Anahtar Kavram
Delegating group management using Administrative Units and least privilege directory roles
Tahmini Süre:1m 30s