Soru

Zorluk: OrtaSelf-Service Password Reset and External Identities

You manage a Microsoft Entra ID tenant. You are configuring Self-Service Password Reset (SSPR) for a pilot group of users. You create a security group named SSPR-Pilot and select it under the Selected SSPR enablement setting. To organize the pilot users, you perform the following actions:

* You add 20 cloud-only users directly as members of SSPR-Pilot.
* You create a second security group named SSPR-SubGroup, add 30 hybrid users to SSPR-SubGroup, and make SSPR-SubGroup a member of SSPR-Pilot.
* You create an Administrative Unit named SSPR-AU, add SSPR-Pilot to SSPR-AU, and assign the Helpdesk Administrator role to a user named Admin1 for the scope of SSPR-AU.

Which users will be able to perform self-service password resets?

  1. Only the 20 cloud-only users added directly to SSPR-Pilot.Cevap
  2. B
    All 50 users (the 20 cloud-only users and the 30 hybrid users).
  3. C
    Only the 20 cloud-only users, but only after Admin1 configures SSPR authentication methods at the Administrative Unit level.
  4. D
    None of the users, until Admin1 is assigned the Owner role for the subscription containing the tenant.

Cevap

Only the 20 cloud-only users added directly to SSPR-Pilot will be able to perform self-service password resets.
Only direct members of the targeted group are enabled when SSPR is configured for a selected group. Because Microsoft Entra ID SSPR does not support nested groups, the users in the nested subgroup are excluded. Additionally, SSPR is configured at the tenant level and does not require subscription RBAC roles or Administrative Unit configuration to function.

Adım Adım Çözüm

1
Identify the SSPR group scoping configuration.
SSPR is enabled for the group SSPR-Pilot.
SSPR enablement determines which users are targeted by the policy based on group membership.
2
Evaluate the membership of the SSPR-Pilot group.
Only the 20 cloud-only users are direct members. The 30 hybrid users are members of SSPR-SubGroup, which is nested inside SSPR-Pilot.
Microsoft Entra ID SSPR does not support nested groups; only direct members are evaluated.
3
Verify if Administrative Unit or Azure RBAC roles impact SSPR user enablement.
Administrative Units and Azure subscription RBAC roles do not change user-level SSPR scope or authentication method configurations.
SSPR is a directory-wide service configured globally in Microsoft Entra ID.

Anahtar Kavram

Microsoft Entra ID SSPR does not support nested groups for policy scoping, and SSPR settings are managed globally rather than via subscription-level RBAC or Administrative Unit scope.
Bu soruyu puanla