Microsoft Azure Administrator — Question 78
You have an Azure subscription named Subscription1 that contains a virtual network named VNet1. VNet1 is in a resource group named RG1.
Subscription1 has a user named User1. User1 has the following roles:
• Reader
• Security Admin
• Security Reader
You need to ensure that User1 can assign the Reader role for VNet1 to other users.
What should you do?
Answer options
- A. Remove User1 from the Security Reader role for Subscript on 1. Assign User1 the Contributor role for RG1.
- B. Assign User1 the Owner role for VNet1.
- C. Remove User1 from the Security Reader and Reader roles for Subscription1. Assign User1 the Contributor role for Subscription 1.
- D. Assign User1 the Contributor role for VNet1.
Correct answer: B
Explanation
The correct answer is B because assigning the Owner role to User1 for VNet1 grants full control over the resource, including the ability to assign roles to other users. The other options either limit User1's permissions or do not provide the necessary access to manage role assignments for VNet1.