Adding only the PA device-management group to the local Administrators group

Design solutions for securing privileged access
Answer Correct answer: A — Only the device-management group (Group2) should be in the local Administrators group; the Security Administrator gets no standing local admin.

You have a Microsoft Entra tenant that contains 10 Windows 11 devices and two groups named Group1 and Group2. The Windows 11 devices are joined to the Microsoft Entra tenant and are managed by using Microsoft Intune. You are designing a privileged access strategy based on the rapid modernization plan (RaMP). The strategy will include the following configurations: • Each user in Group1 will be assigned a Windows 11 device that will be configured as a privileged access device. • The Security Administrator role will be mapped to the privileged access security level. • The users in Group1 will be assigned the Security Administrator role. • The users in Group2 will manage the privileged access devices. You need to configure the local Administrators group for each privileged access device. The solution must follow the principle of least privilege. What should you include in the solution?

  1. Only add Group2 to the local Administrators group. Correct Answer
  2. Configure Windows Local Administrator Password Solution (Windows LAPS) in legacy Microsoft LAPS emulation mode.
  3. Add Group2 to the local Administrators group. Add the user that is assigned the Security Administrator role to the local Administrators group of the user's assigned privileged access device.

Community Votes

A
62%
C
38%

62% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

PAW/RaMP guidance removes local administrator rights from the privileged user; only the device-management group (Group2) belongs in the local Administrators group, so adding the Security Administrator as a local admin (option C) violates least privilege.

For a Rapid Modernization Plan (RaMP) privileged access device, the local Administrators group should contain only the group that manages the privileged access devices (Group2). The assigned Security Administrator (Group1) is granted no standing local administrator rights, following least privilege and PAW guidance.

Adding the Security Administrator user to the local Administrators group of their own device (option C) — PAW/RaMP requires no standing local admin for the privileged user, so only the managing group (Group2) should be a local admin.

Community Discussion (5 comments)

424ede1 👍 1 Selected: A
Under the RaMP guidelines, you want to enforce the principle of least privilege. To minimize the risk of lateral movement or compromise, these privileged access devices should not grant local administrator rights to the security administrators.
olsookie 👍 2 Selected: A
To follow the principle of least privilege, you should include Option A: Only add Group2 to the local Administrators group in your solution. This ensures that only the users responsible for managing the privileged access devices have administrative rights, minimizing the risk of unnecessary access. https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/best-practices https://learn.microsoft.com/en-us/entra/identity/devices/assign-local-admin
devop23 👍 2 Selected: A
Answer is A: https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-deployment Remove local admin rights This method requires that users of the VIP, DevOps, and Privileged workstations have no administrator rights on their machines. Group2 users will manage these devices so they should have local admin access anyway. So option C is eliminated. Option B doesn't make sense here.
Er_01 👍 2 Selected: C
https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-deployment It says not to add anyone to admin on privileged wa. So A and C are against best practice. B will not work as legacy laps not be used on cloud joined was. So the best answer would be C because it allows for different group to manage and only 1 person to use. Bad question.
676ae1a 👍 1 Selected: C
Respuesta correcta

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In a Rapid Modernization Plan (RaMP) privileged access workstation (PAW) deployment, the local Administrators group on each privileged access device contains only the group that administers those devices (Group2). The assigned privileged user (the Security Administrator in Group1) is intentionally given NO standing local administrator rights, because PAW guidance requires removing local admin rights from privileged workstation users to prevent lateral movement.

Why the Other Options Are Wrong

Option C adds the Security Administrator to the local Administrators group of their assigned device, which directly violates the least-privilege PAW principle of no local admin for the user. Option B (Windows LAPS in legacy emulation mode) is about local password management and does not apply to Microsoft Entra-joined cloud devices, nor does it address the local Administrators group membership the question asks for.

Community Comment Notes

The community favored A (63 votes). The privileged-access-deployment documentation states that VIP/DevOps/privileged workstation users should have no administrator rights on their machines, and that Group2 manages the devices. A minority (C, 38 votes) suggested adding the user, but that conflicts with the documented remove-local-admin principle.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide