Which least-privilege role should be assigned to User1 so they can create groups, create access reviews for role-assignable groups, and assign Azure AD roles to groups?
Choose an answer
Tap an option to check your answer.
Correct answer: Privileged role administrator.
Why this is the answer
The Privileged role administrator role is the correct choice because it grants the necessary permissions to manage all aspects of Azure AD roles, including assigning roles to groups, creating new groups, and creating access reviews for role-assignable groups. The Groups administrator role allows managing groups but not assigning Azure AD roles. The Authentication administrator manages authentication methods and policies, not role assignments or group creation. The Identity Governance Administrator manages access reviews and entitlements but lacks the broad permissions for creating groups and assigning all Azure AD roles that a Privileged role administrator possesses.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed