You have an Azure subscription with a user named Admin1 and a resource group RG1. RG1 contains an Azure Network Watcher instance named NW1. You must allow Admin1 to place a lock on NW1 while following the principle of least privilege. Which built-in role should you assign to Admin1?
Choose an answer
Tap an option to check your answer.
Correct answer: User Access Administrator.
Why this is the answer
The User Access Administrator role is the correct choice because it allows the user to manage user access to Azure resources, including the ability to place or remove locks. This aligns with the principle of least privilege, as it grants only the necessary permissions for managing access and locks, not broader resource management. The Resource Policy Contributor role is incorrect because it focuses on managing policies, not resource locks or user access. The Network Contributor role is incorrect as it provides permissions to manage networking resources but not the ability to apply locks. The Monitoring Contributor role is incorrect because it grants permissions to manage monitoring resources, which is unrelated to placing locks on a Network Watcher instance.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed