You have a subscription that contains a user named User1. You need to allow User1 to create managed identities while applying the principle of least privilege. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a resource group and assign User1 to the Managed Identity Contributor role..
Why this is the answer
The correct approach is to create a resource group and assign User1 the Managed Identity Contributor role. This role grants permissions to create, delete, and assign a managed identity to an Azure resource, adhering to the principle of least privilege by scoping the permissions to a specific resource group. Creating a management group and assigning the Hybrid Identity Administrator Azure AD role is incorrect because management groups are for organizing subscriptions, not for granting fine-grained resource permissions, and the Hybrid Identity Administrator role is too broad, providing permissions for configuring synchronization between on-premises AD and Azure AD, not for managing managed identities. Creating a management group and assigning the Managed Identity Operator role is incorrect because, while the role is relevant, applying it at the management group level grants permissions across all subscriptions within that group, violating the principle of least privilege. Creating an organizational unit (OU) and assigning User1 the User administrator Azure Active Directory (Azure AD) role is incorrect because OUs are an Active Directory Domain Services concept and do not apply to Azure resource management. The User administrator role is also too broad, allowing management of all aspects of users and groups, not just managed identities.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed