Least privilege role to review Identity Protection risky users
You have a Microsoft 365 subscription that contains an Azure AD tenant named contoso.com. The tenant includes a user named User1. You enable Azure AD Identity Protection. You need to ensure that User1 can review the list in Azure AD Identity Protection of users flagged for risk. The solution must use the principle of least privilege. To which role should you add User1?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tested: which built-in role can view Identity Protection risky users under least privilege; the trap is assuming Reports Reader or full Global Administrator is needed.
Azure AD Identity Protection flags users for risk, and reviewing the flagged users list requires the right least-privilege role. This page confirms that Security Administrator (C) is the correct choice when Security Reader is not offered.
Choosing Reports Reader (D) because it can read sign-in and audit reports, but it does not grant access to the Identity Protection risky users list.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Security Administrator (C) is the correct least-privilege role among the available options because it can review the Azure AD Identity Protection list of users flagged for risk without granting full tenant control. Microsoft's built-in role guidance grants Identity Protection read access to Security Reader, Global Reader, Security Administrator, and Global Administrator; with Security Reader and Global Reader absent, Security Administrator is the closest least-privileged match. Although Security Administrator can also manage security settings, its read capability for risky users satisfies the requirement, and no lower-privileged option in this list provides that access. Choosing Global Administrator would violate least privilege because it can manage every aspect of the Microsoft 365 tenant. Therefore C meets the question's intent.Why the Other Options Are Wrong
A. Global Administrator grants full control over the tenant and all security features, which far exceeds the read-only review requirement and breaks least privilege. B. Service Administrator manages service requests, billing, and support tickets; it has no access to Identity Protection risky users or security reports. D. Reports Reader can read sign-in and audit reports and Office 365 usage reports, but it does not include the Azure AD Identity Protection risky users list; learners often confuse it with the Security Reader role, which is the actual read-only security role. Because Security Reader is not offered, the next least-privileged role that can review flagged users is Security Administrator. This is why C is the intended answer.Community Comment Notes
As solderboy noted, the risky sign-ins reports are available to Security Administrator, Global Administrator, and Security Reader, and the question appears in multiple versions where Security Reader is sometimes an option. APK1 pointed out that since there is "no Security Reader provided in the answers list," Security Administrator becomes the correct answer and that Reports Reader "is not Security Reader." Ody shared a hands-on claim that a Reports Reader can "review and download the risk reports" after logging into Entra ID, but the official built-in role definitions reserve Identity Protection read access for Security Reader, not Reports Reader. The overwhelming community vote for C reflects the least-privilege interpretation when Security Reader is missing. So the community consensus supports the selected answer.Official Reference
Exam Strategy
When Security Reader is not among the options, look for Security Administrator as the least-privileged built-in role that can read Identity Protection risk data. Do not choose Reports Reader based on its report-reading description; it lacks the security report scope needed for risky users.
Frequently Asked Questions
Why is Reports Reader (D) not sufficient for Azure AD Identity Protection risky users?
Reports Reader can view sign-in and audit reports but does not include the Identity Protection risky users list. Security Reader is the read-only security role for that data, so D is not correct.
Why is Global Administrator (A) not the least-privilege choice?
Global Administrator grants full tenant control and far exceeds the review-only requirement. Security Administrator provides the needed Identity Protection access with fewer privileges.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →