Q: 15
HOTSPOT You have a Microsoft 365 tenant that has 5,000 users. One hundred of the users are executives. The executives have a dedicated support team. You need to ensure that the support team can reset passwords and manage multi-factor authentication (MFA) settings for only the executives. The solution must use the principle of least privilege. Which object type and Azure Active Directory (Azure AD) role should you use? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
Your Answer
Discussion
Isn't the combo of Administrative Unit and Authentication Administrator the best fit here? Makes sense since you only want to scope access for execs and limit what support team can do. Nice, clear question setup.
Why not Password Administrator? I get that it can reset passwords, but only Authentication Administrator can actually manage MFA too, so seems like a trap for folks who miss the MFA part.
Be respectful. No spam.
