You have a Recovery Services vault (Vault1). To enable multi-user authorization (MAU) for the vault, which resource must you create first?
Choose an answer
Tap an option to check your answer.
Correct answer: A resource guard.
Why this is the answer
To enable multi-user authorization (MAU) for a Recovery Services vault, you must first create a resource guard. A resource guard defines the authorization rules and approvers for critical operations on the vault, ensuring that multiple authorized users are required to approve sensitive actions like deleting backups or changing replication settings. This adds an extra layer of security against accidental or malicious actions. An administrative unit is used for delegating administrative permissions in Azure Active Directory, not for securing Recovery Services vault operations. A managed identity is an identity used by Azure resources to authenticate to services that support Azure AD authentication, not for defining authorization policies for vault operations. A custom Azure role defines a set of permissions, but MAU specifically requires a resource guard to enforce multi-user approval for critical operations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed