Adding only the PA device-management group to the local Administrators group
You have a Microsoft Entra tenant that contains 10 Windows 11 devices and two groups named Group1 and Group2. The Windows 11 devices are joined to the Microsoft Entra tenant and are managed by using Microsoft Intune. You are designing a privileged access strategy based on the rapid modernization plan (RaMP). The strategy will include the following configurations: • Each user in Group1 will be assigned a Windows 11 device that will be configured as a privileged access device. • The Security Administrator role will be mapped to the privileged access security level. • The users in Group1 will be assigned the Security Administrator role. • The users in Group2 will manage the privileged access devices. You need to configure the local Administrators group for each privileged access device. The solution must follow the principle of least privilege. What should you include in the solution?
Community Votes
62% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
PAW/RaMP guidance removes local administrator rights from the privileged user; only the device-management group (Group2) belongs in the local Administrators group, so adding the Security Administrator as a local admin (option C) violates least privilege.
For a Rapid Modernization Plan (RaMP) privileged access device, the local Administrators group should contain only the group that manages the privileged access devices (Group2). The assigned Security Administrator (Group1) is granted no standing local administrator rights, following least privilege and PAW guidance.
Adding the Security Administrator user to the local Administrators group of their own device (option C) — PAW/RaMP requires no standing local admin for the privileged user, so only the managing group (Group2) should be a local admin.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In a Rapid Modernization Plan (RaMP) privileged access workstation (PAW) deployment, the local Administrators group on each privileged access device contains only the group that administers those devices (Group2). The assigned privileged user (the Security Administrator in Group1) is intentionally given NO standing local administrator rights, because PAW guidance requires removing local admin rights from privileged workstation users to prevent lateral movement.Why the Other Options Are Wrong
Option C adds the Security Administrator to the local Administrators group of their assigned device, which directly violates the least-privilege PAW principle of no local admin for the user. Option B (Windows LAPS in legacy emulation mode) is about local password management and does not apply to Microsoft Entra-joined cloud devices, nor does it address the local Administrators group membership the question asks for.Community Comment Notes
The community favored A (63 votes). The privileged-access-deployment documentation states that VIP/DevOps/privileged workstation users should have no administrator rights on their machines, and that Group2 manages the devices. A minority (C, 38 votes) suggested adding the user, but that conflicts with the documented remove-local-admin principle.Official Reference
Related Analysis
Practice All SC-100 Questions
Access 110 questions with complete answers and detailed explanations.
View Full SC-100 Practice Test →