Using the Permissions Management analytics dashboard to find privileged role assignments

Design solutions for securing privileged access
Answer Correct answer: D — The Permissions Management Analytics dashboard shows privileged role assignments and risks across subscriptions, minimizing administrative effort.

You have multiple Azure subscriptions that each contains multiple resource groups. You need to identify the privileged role assignments in each subscription and any associated security risks. The solution must minimize administrative effort. What should you use?

  1. access reviews in Privileged Identity Management (PIM)
  2. access reviews in Microsoft Entra ID Identity Governance
  3. Microsoft Defender External Attack Surface Management (Defender EASM) discovery
  4. the Analytics dashboard in Microsoft Entra Permissions Management Correct Answer

Community Votes

D
64%
A
36%

64% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Permissions Management analytics aggregates privileged permissions and risk across many subscriptions; PIM access reviews are per-directory and require per-assignment review setup, so they do not give a single cross-subscription privileged-role risk view.

To identify privileged role assignments and their security risks across multiple Azure subscriptions with minimal effort, use the Analytics dashboard in Microsoft Entra Permissions Management, which provides cross-subscription visibility into permissions and risk.

Choosing access reviews in PIM (A) — they review individual assignments but do not provide a consolidated cross-subscription analytics view of privileged role assignments and associated risk.

Community Discussion (5 comments)

424ede1 👍 1 Selected: D
D. the Analytics dashboard in Microsoft Entra Permissions Management https://learn.microsoft.com/en-us/entra/permissions-management/usage-analytics-users#apply-filters-by-identity-type
sweetykaur 👍 1 Selected: A
A. Microsoft Defender for Identity Microsoft Defender for Identity (formerly Azure Advanced Threat Protection) can help you mark sensitive groups and monitor changes to these groups. By integrating it with Microsoft Sentinel, you can set up alerts to be triggered whenever there are changes to Group1, ensuring that any modifications are promptly detected and addressed.
Ali96 👍 3 Selected: A
A. access reviews in Privileged Identity Management (PIM)
AlbertE1nstein 👍 2 Selected: D
D. the Analytics dashboard in Microsoft Entra Permissions Management
oscarpopi 👍 4 Selected: D
Identify the p[riviledged role in multiple subscriptions, Access Reviews does not do that. EPM does.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra Permissions Management (CIEM) includes an Analytics dashboard that aggregates permissions and risk across many subscriptions and identities in one place, letting you identify privileged role assignments and associated risks with minimal administrative effort.

Why the Other Options Are Wrong

Access reviews in PIM (A) and in Identity Governance (B) evaluate whether specific users should retain assignments but do not produce a single cross-subscription privileged-role risk view. Defender EASM discovery (C) discovers external attack surface, not internal privileged role assignments.

Community Comment Notes

The community favored D (64 votes). Comments note that access reviews do not identify unused or risky privileged assignments across subscriptions, whereas the Permissions Management Analytics dashboard does; a minority (A, 36 votes) suggested PIM access reviews.

Official Reference

Related Analysis

Practice All SC-100 Questions

Access 110 questions with complete answers and detailed explanations.

View Full SC-100 Practice Test →

← Back to SC-100 Study Guide