You plan to enable passwordless authentication in an Azure AD tenant and need User1 to be able to enable the combined registration experience using least privilege. Which role should you assign to User1?
Choose an answer
Tap an option to check your answer.
Correct answer: Global administrator.
Why this is the answer
The Global administrator role is the only built-in Azure AD role that has the necessary permissions to enable the combined security information registration experience for all users. This setting is a tenant-wide configuration that impacts how users register for multi-factor authentication (MFA) and self-service password reset (SSPR), requiring the highest level of administrative privilege. While Security administrator and Authentication administrator roles manage authentication-related settings, they lack the broad tenant-level permissions to enable this specific combined registration experience. Privileged role administrator manages role assignments but does not configure tenant-wide authentication settings.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed