User1 must be able to assign a policy to the tenant root management group. What should you do to enable this?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign the Global administrator role to User1, and then instruct User1 to configure access management for Azure resources..
Why this is the answer
To assign a policy at the tenant root management group, User1 needs elevated permissions at the tenant level. The Global Administrator role in Azure Active Directory (Azure AD) is a highly privileged role that can manage all administrative aspects across Azure AD and Azure services. Once assigned, a Global Administrator can elevate their access to manage all Azure subscriptions and management groups, including the tenant root. This elevation allows them to then configure access management for Azure resources, which includes assigning policies at the root management group. Assigning the Owner role at the subscription level is insufficient because the tenant root management group is above the subscription scope. Creating a new management group and delegating ownership only grants control over that specific new group, not the tenant root. Modifying conditional access policies is unrelated to granting permissions for policy assignment at the management group level.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed