Q: 15
HOTSPOT You have a Microsoft 365 tenant that has 5,000 users. One hundred of the users are executives. The executives have a dedicated support team. You need to ensure that the support team can reset passwords and manage multi-factor authentication (MFA) settings for only the executives. The solution must use the principle of least privilege. Which object type and Azure Active Directory (Azure AD) role should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Your Answer
Discussion
Isn't the combo of Administrative Unit and Authentication Administrator the best fit here? Makes sense since you only want to scope access for execs and limit what support team can do. Nice, clear question setup.
I get why some folks pick Password Administrator here, but that role can't handle MFA settings. To fully cover both password resets and MFA for execs (while sticking to least privilege), Administrative Unit plus Authentication Administrator is the way to go. Kinda easy to miss if you gloss over the MFA part.
Yeah, agreed with Sara here. Administrative Unit plus Authentication Administrator.
Why not Password Administrator? I get that it can reset passwords, but only Authentication Administrator can actually manage MFA too, so seems like a trap for folks who miss the MFA part.
Password Administrator and security group. I thought this combo works because Password Administrator can reset passwords, and if you put execs in a special group, that's scoping it too right? Not 100% sure about MFA though.
Administrative unit plus Authentication administrator, but only if the MFA part is required. If they just wanted password resets, Password Administrator could work, so depends how strict they're grading this one.
Be respectful. No spam.
