You have an Azure Active Directory tenant and a root management group. Ten subscriptions are added to the root management group. Before creating an Azure Blueprints definition that will be stored at the root management group level, which action must you perform first?
Choose an answer
Tap an option to check your answer.
Correct answer: Modify the role-based access control (RBAC) role assignments for the root management group..
Why this is the answer
To create an Azure Blueprint definition at the root management group level, you need the appropriate permissions. Specifically, the "Owner" or "Contributor" role on the management group is required to create and manage blueprints. Modifying the RBAC role assignments ensures that the user or service principal attempting to create the blueprint has these necessary permissions. Adding an Azure Policy definition is not a prerequisite for creating a blueprint; policies can be included within a blueprint but aren't needed beforehand. Creating a user-assigned identity or a service principal might be necessary for certain blueprint components or assignments, but they are not a prerequisite for creating the blueprint definition itself. The fundamental requirement is sufficient permissions on the scope where the blueprint will be defined.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed