Exam SC-300 Topic 3 Question 15 Discussion
Actual exam question for Microsoft's SC-300 exam
Question #: 15
Topic #: 3
Question #: 15
Topic #: 3
You have a Microsoft Entra tenant that uses Microsoft Entra ID Protection and contains the users shown in the following table.

You need to implement a Conditional Access policy that enforces a remediation requirement for risky users.
Which users can create the policy?

You need to implement a Conditional Access policy that enforces a remediation requirement for risky users.
Which users can create the policy?
Suggested Answer: B Vote an answer
Both User1 (Conditional Access Administrator) and User2 (Security Administrator) can create this Conditional Access policy.
User1 (Conditional Access Administrator): This role is explicitly designed with the least-privileged permissions needed to create, manage, and edit Microsoft Entra Conditional Access policies.
User2 (Security Administrator): This role has broad security management permissions in the tenant, which include full capabilities to create and manage Conditional Access policies, as well as handling Microsoft Entra ID Protection risk signals.
Incorrect:
User3 (Authentication Administrator): This role can view, set, and reset authentication method information for non-administrative users. It does not possess the permissions required to create or modify Conditional Access policies.
Reference:
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference
User1 (Conditional Access Administrator): This role is explicitly designed with the least-privileged permissions needed to create, manage, and edit Microsoft Entra Conditional Access policies.
User2 (Security Administrator): This role has broad security management permissions in the tenant, which include full capabilities to create and manage Conditional Access policies, as well as handling Microsoft Entra ID Protection risk signals.
Incorrect:
User3 (Authentication Administrator): This role can view, set, and reset authentication method information for non-administrative users. It does not possess the permissions required to create or modify Conditional Access policies.
Reference:
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference
by Dorothy at Sep 13, 2026, 06:39 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).