You have 15 Azure subscriptions and an Azure AD tenant with a security group named Group1. You will buy additional subscriptions. Ensure Group1 can manage role assignments for all existing and future subscriptions while following least privilege and minimizing administrative effort. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign Group1 the User Access Administrator role for the root management group..
Why this is the answer
Assigning Group1 the User Access Administrator role at the root management group level ensures they can manage role assignments across all current and future subscriptions. This role grants permission to manage access to Azure resources, which includes assigning and removing roles. Applying it at the root management group provides inheritance to all subscriptions, minimizing administrative effort. This aligns with the principle of least privilege because the User Access Administrator role specifically focuses on access management, unlike the Owner role, which grants full control over resources. The Owner role is too permissive as it allows full control, not just role assignment management. Creating a new management group and assigning roles there would not cover existing subscriptions outside that new group, failing to meet the requirement for "all existing and future subscriptions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed