An organization has a Microsoft Entra ID tenant. The tenant contains a dynamic security group named IT-Personnel and an administrative unit named IT-AU. The IT-Personnel group is a member of IT-AU. A user named Admin1 is assigned the Groups Administrator role scoped to IT-AU. You need to determine if Admin1 can update the dynamic query that defines the membership of the IT-Personnel group.
Is the statement 'Admin1 can modify the dynamic membership rule of the IT-Personnel group' true or false?
Cevap: Cevap
Cevap
False
The correct answer is False because administrative unit-scoped directory roles do not grant permissions to modify the membership rules of dynamic groups. Changing the query definition of a dynamic group requires a tenant-wide administrator role.
Adım Adım Çözüm
Anahtar Kavram
Delegated administrative permissions and their limitations on dynamic groups within Microsoft Entra ID Administrative Units.