Your onboarding automation needs permission to connect new servers to Azure Arc, and your operations team needs to manage extensions and guest configuration on Arc-enabled servers but must not delete resources. How should you assign roles and organize resources?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign the Azure Connected Machine Onboarding role to the service principal at the subscription or management group scope used for onboarding., Assign the Azure Connected Machine Resource Administrator role to the operations team at the resource group scope where Arc-enabled servers are placed..
Why this is the answer
The Azure Connected Machine Onboarding role grants the necessary permissions for a service principal to onboard new servers to Azure Arc, making it ideal for automation at a broad scope (subscription or management group). The Azure Connected Machine Resource Administrator role allows the operations team to manage extensions and guest configurations on Arc-enabled servers, aligning with their needs, but crucially, it does not permit resource deletion. Applying this role at the resource group scope ensures granular control over the specific Arc-enabled servers. The Virtual Machine Contributor role is too broad and grants permissions beyond what the operations team requires, including deletion. Keeping Arc-enabled servers in the same resource group as production Azure VMs complicates access control and doesn't align with the principle of least privilege, as it could inadvertently grant operations teams permissions to Azure VMs they shouldn't manage.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed