Which Role Lets a User Review Risky Users in Entra ID Protection?
You have a Microsoft 365 subscription that contains a Microsoft Entra tenant named contoso.com. The tenant includes a user named User1. You plan to use Microsoft Entra ID Protection. You need to ensure that User1 can review the list in Microsoft Entra ID Protection of users flagged for risk. The solution must use the principle of least privilege. To which role should you add User1?
Community Votes
67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests which built-in Microsoft Entra role grants read visibility into Identity Protection risk detections as cheaply as possible, and the trap is confusing report-only roles such as Reports Reader with true security-read roles.
Microsoft Entra ID Protection flags risky users, and reviewing that list requires a read-only security role rather than an administrative one. This page establishes that a Security Reader assignment (A) satisfies the least-privilege requirement for User1.
The frequent wrong pick is User Administrator, because it sounds like the role that manages user objects, but it has no permission to read Identity Protection risk data and violates least privilege for a review task.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
User1 must be able to open Microsoft Entra ID Protection and view the Risky users report, which is a read-only security operation over the tenant's risk detections. Security Reader is a built-in Microsoft Entra role that grants read-only access to security-related information, including Identity Protection risk detections and risky users, without allowing any configuration change. Because the requirement is only to review the list, Security Reader gives exactly the needed permission and nothing more, which is why least privilege is satisfied by option A. The community consensus matches this reasoning: as pxeboot wrote, "Looks correct", and another learner summarised that Security Reader "allows users to view security reports and configurations, including risk detection information."Why the Other Options Are Wrong
Reports Reader is limited to usage reporting and the reports dashboard (sign-in and audit report surfaces); it does not grant access to the Identity Protection Risky users blade, so it fails the functional requirement in B. Service Administrator manages service requests and the service health dashboard, which has nothing to do with risk detections or user risk state, so C is irrelevant. User Administrator can create and manage users and group membership but cannot read Identity Protection risk data, so D grants a powerful write-capable user-management role while still not delivering the required visibility. Only Security Reader is both sufficient and minimal.Community Comment Notes
Learners split roughly two to one in favour of A, and the reasoning recorded by SummerK — that Security Reader is "designed for this purpose" and aligns with minimal privilege — reflects the vendor's own role description. One entry labelled answer D talks about Attack simulation training in Microsoft Defender for Office 365, which is unrelated content from a different question thread and does not analyse the Identity Protection risky users list at all. The general agreement in the thread is that a read-only security role, not a user-management role, is what makes the Risky users report visible to User1.Official Reference
Exam Strategy
When an MS-102 item asks for the least privilege to perform an action, first classify the action as read-only security, read-only reporting, or administrative — Identity Protection risk review is read-only security, so Security Reader wins. Remember that User Administrator and Service Administrator are operational write roles and never satisfy a pure review requirement.
Frequently Asked Questions
Why is Reports Reader not enough to see the risky users list in Entra ID Protection?
Reports Reader only covers usage and sign-in/audit reporting surfaces. It does not include the Identity Protection risk detections permission, so the Risky users blade stays inaccessible.
Would User Administrator give User1 access to Identity Protection risky users?
No. User Administrator manages user objects and group membership but has no permission to read Identity Protection risk data, and it would exceed least privilege for a review task.
Related Analysis
Practice All MS-102 Questions
Access 111 questions with complete answers and detailed explanations.
View Full MS-102 Practice Test →