You need to let a user manage Security defaults and create Conditional Access policies while following least-privilege principles. Which Azure AD role should you assign to that user?
Choose an answer
Tap an option to check your answer.
Correct answer: Conditional Access Administrator.
Why this is the answer
The Conditional Access Administrator role is the most appropriate choice because it grants permissions specifically for managing Conditional Access policies, as well as Security defaults, which are a foundational set of security policies. This aligns with the principle of least privilege, ensuring the user has only the necessary permissions. Global Administrator is incorrect because it provides unrestricted access to all administrative functions in Azure AD, far exceeding the required permissions. Security Administrator is incorrect as it focuses on managing security-related features like security settings, reports, and alerts, but does not include the ability to manage Conditional Access policies or Security defaults. Intune Administrator is incorrect because its scope is limited to managing Microsoft Intune and mobile device management, which is unrelated to Conditional Access or Security defaults.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed