The on-premises domain adatum.com syncs to Azure AD and Azure AD Connect is installed on Server1. To allow an adatum.com domain administrator to modify the synchronization settings using least privilege, which Azure AD role should you assign?
Choose an answer
Tap an option to check your answer.
Correct answer: Global administrator.
Why this is the answer
The Global Administrator role is required because modifying Azure AD Connect synchronization settings, especially those impacting directory synchronization, demands the highest level of administrative privilege within Azure AD. This role grants full control over all administrative functions in Azure AD, including the ability to configure and manage Azure AD Connect. The Security Administrator role is incorrect because it focuses on security-related tasks like managing security settings, reports, and compliance, but does not encompass the full scope of Azure AD Connect configuration. The User Administrator role is also incorrect as it is limited to managing users and groups, and lacks the permissions needed to modify directory synchronization settings.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed