Least privilege role to review Identity Protection risky users

Implement and manage secure access Manage roles and role groups
Answer Correct answer: C — Assign User1 the Security Administrator role to review the Azure AD Identity Protection users flagged for risk list with least privilege.

You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1. You enable Azure AD Identity Protection. You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege. To which role should you add User1?

  1. Global Administrator
  2. Service Administrator
  3. Security Administrator Correct Answer
  4. Reports Reader

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tested: which built-in role can view Identity Protection risky users under least privilege; the trap is assuming Reports Reader or full Global Administrator is needed.

Azure AD Identity Protection flags users for risk, and reviewing the flagged users list requires the right least-privilege role. This page confirms that Security Administrator (C) is the correct choice when Security Reader is not offered.

Choosing Reports Reader (D) because it can read sign-in and audit reports, but it does not grant access to the Identity Protection risky users list.

Community Discussion (4 comments)

solderboy 👍 19 Selected: C
The risky sign-ins reports are available to users in the following roles: ✑ Security Administrator ✑ Global Administrator ✑ Security Reader There are several versions of this question in the exam. The question has three possible correct answers: 1. Security Reader 2. Security Administrator 3. Global Administrator Other incorrect answer options you may see on the exam include the following: 1. Service Administrator. 2. Reports Reader 3. Compliance Administrator
Ody 👍 1 Selected: D
I am not disagreeing with the documentation people have posted, but if you set it up and make a user a Reports Reader, that user can login to Entra ID, go to Identity Protection and review and download the risk reports. Reports Reader: Users with this role can view usage reporting data and the reports dashboard in Office 365 admin center and the adoption context pack in Power BI. Additionally, the role provides access to sign-on reports and activity in Microsoft Entra ID and data returned by the Microsoft Graph reporting API. A user assigned to the Reports Reader role can access only relevant usage and adoption metrics.
APK1 👍 2 Selected: C
Since there is no Security Reader provided in the answers list, Security Administrator is the correct answer. Report Reader (Can read sign-in and audit reports) is not Security Reader
SBGM 👍 2 Selected: C
Solder is correct in my opinion

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Security Administrator (C) is the correct least-privilege role among the available options because it can review the Azure AD Identity Protection list of users flagged for risk without granting full tenant control. Microsoft's built-in role guidance grants Identity Protection read access to Security Reader, Global Reader, Security Administrator, and Global Administrator; with Security Reader and Global Reader absent, Security Administrator is the closest least-privileged match. Although Security Administrator can also manage security settings, its read capability for risky users satisfies the requirement, and no lower-privileged option in this list provides that access. Choosing Global Administrator would violate least privilege because it can manage every aspect of the Microsoft 365 tenant. Therefore C meets the question's intent.

Why the Other Options Are Wrong

A. Global Administrator grants full control over the tenant and all security features, which far exceeds the read-only review requirement and breaks least privilege. B. Service Administrator manages service requests, billing, and support tickets; it has no access to Identity Protection risky users or security reports. D. Reports Reader can read sign-in and audit reports and Office 365 usage reports, but it does not include the Azure AD Identity Protection risky users list; learners often confuse it with the Security Reader role, which is the actual read-only security role. Because Security Reader is not offered, the next least-privileged role that can review flagged users is Security Administrator. This is why C is the intended answer.

Community Comment Notes

As solderboy noted, the risky sign-ins reports are available to Security Administrator, Global Administrator, and Security Reader, and the question appears in multiple versions where Security Reader is sometimes an option. APK1 pointed out that since there is "no Security Reader provided in the answers list," Security Administrator becomes the correct answer and that Reports Reader "is not Security Reader." Ody shared a hands-on claim that a Reports Reader can "review and download the risk reports" after logging into Entra ID, but the official built-in role definitions reserve Identity Protection read access for Security Reader, not Reports Reader. The overwhelming community vote for C reflects the least-privilege interpretation when Security Reader is missing. So the community consensus supports the selected answer.

Official Reference

Exam Strategy

When Security Reader is not among the options, look for Security Administrator as the least-privileged built-in role that can read Identity Protection risk data. Do not choose Reports Reader based on its report-reading description; it lacks the security report scope needed for risky users.

Frequently Asked Questions

Why is Reports Reader (D) not sufficient for Azure AD Identity Protection risky users?

Reports Reader can view sign-in and audit reports but does not include the Identity Protection risky users list. Security Reader is the read-only security role for that data, so D is not correct.

Why is Global Administrator (A) not the least-privilege choice?

Global Administrator grants full tenant control and far exceeds the review-only requirement. Security Administrator provides the needed Identity Protection access with fewer privileges.

Related Analysis

Practice All MS-102 Questions

Access 111 questions with complete answers and detailed explanations.

View Full MS-102 Practice Test →

← Back to MS-102 Study Guide