Subscription1 contains VNet1 in RG1. User1 currently has the Reader, Security Admin, and Security Reader roles. You need to allow User1 to assign the Reader role on VNet1 to other users. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign User1 the User Access Administrator role for VNet1..
Why this is the answer
The User Access Administrator role is specifically designed to allow users to manage user access to Azure resources. By assigning User1 this role for VNet1, they gain the necessary permissions to assign other roles, such as the Reader role, to other users for that specific resource. The Reader, Security Admin, and Security Reader roles do not include permissions to manage role assignments. Removing User1 from existing roles is unnecessary and would remove legitimate access. The Network Contributor role allows management of network resources but does not grant permissions to manage role assignments. Assigning it at the resource group level (RG1) would also not provide the required role assignment capabilities for VNet1.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed