Microsoft 365 Administrator — Question 117

You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1.

You enable Azure AD Identity Protection.

You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege.

To which role should you add User1?

Answer options

Correct answer: B

Explanation

The Security Administrator role is necessary for User1 to access the Azure AD Identity Protection features, which include reviewing risky users. The other roles, such as Compliance Administrator and User Administrator, do not provide the specific permissions required to manage or review risk flags in Azure AD Identity Protection.