Exam SC-300 Topic 3 Question 10 Discussion

Actual exam question for Microsoft's SC-300 exam
Question #: 10
Topic #: 3
Hotspot Question
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

You plan to implement Azure AD Identity Protection.
Which users can configure the user risk policy, and which users can view the risky users report?
To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Suggested Answer:


Explanation:
Box 1: User 3 only
Box 2: User 3 and User 4 only
Conditional Access Administrator
- Does not have access to Identity Protection | User risk policy
- Does not have "Grants access to Risky Users Report"
Authentication Administrator
- Does not have access to Identity Protection | User risk policy
- Does not have "Grants access to Risky Users Report"
Security Administrator
- Has update access to Identity Protection | User risk policy
microsoft.directory/identityProtection/allProperties/update = Update all resources in Azure AD Identity Protection
- Grants access to Risky Users Report
Security Operator
- Has only read access to Identity Protection | User risk policy
microsoft.directory/identityProtection/allProperties/allTasks = Create and delete all resources, and read and update standard properties in Azure AD Identity Protection
- Grants access to Risky Users Report
Reference:
https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity- protection

by Arvin at Aug 01, 2026, 01:41 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10