What Should You Do First to Give a User Permissions Management Access?
You have an Azure subscription that contains a user named User1. The subscription is onboarded to Microsoft Entra Permissions Management. You need to provide User1 with access to Permissions Management. The solution must meet the following requirements: • Follow the principle of least privilege. • Minimize administrative effort. What should you do first?
Community Votes
65% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests that Permissions Management access is group-based; the common trap is choosing direct role assignment to a user because it looks like least privilege with minimal effort.
Microsoft Entra Permissions Management grants product access through Microsoft Entra security groups, so the first step for User1 is creating a group in the Microsoft Entra admin center. This page confirms option B and explains why a direct Entra role assignment to the user does not satisfy the group-based access model.
Choosing D (assign a role directly to User1) because it seems to grant access in one step, but Permissions Management does not provide product-level access through direct user role assignment; it requires a Microsoft Entra security group first.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Entra Permissions Management does not grant product access by assigning a Microsoft Entra directory role directly to a user; it relies on group-based entitlements. To add User1, you must first create a Microsoft Entra security group in the Microsoft Entra admin center, add User1 to it, and then assign the required Permissions Management role (for example, Viewer or Administrator) to that group. Because the group becomes the unit of authorization, the role can be scoped to only the cloud environments and tasks User1 needs, which satisfies least privilege. This also minimizes future administrative effort: additional users can gain the same access by group membership rather than by repeating per-user assignments. Therefore the first action is creating the security group (B).Why the Other Options Are Wrong
Option A (Role/Policy Template subtab) is about defining reusable Permissions Management templates for role and policy configuration, not about granting a specific user access; creating a template does not add User1 to the product. Option C (My Requests subtab) is a self-service request workflow for resources or roles, not the administrative first step to provision access, and it would still depend on the underlying group and role structure. Option D (assign a role directly to User1 from the Microsoft Entra admin center) is the most tempting distractor because it appears to follow least privilege with minimal steps, but Permissions Management access is group-based, so a direct Entra role assignment does not provide the granular product-level access this scenario requires. In short, D risks granting a broad directory role rather than least-privilege Permissions Management access, and it bypasses the required group membership.Community Comment Notes
The majority of commenters (65 votes for B) support the group-first approach, and Sneekygeek points out that "Permissions Management has its own group-based access system" for granular control over cloud environments and permissions. Penatuna reinforces this with the official requirement that "Permissions Management entitlements work through group-based access" and that "you must add a user to a group through Microsoft Entra ID." A dissenting group (dvmhike, Sozo, Frank9020, Labelfree) argues for D, with Labelfree asking "where are we assigning anything in B?" and calling for direct role assignment to meet least privilege; however, their reasoning overlooks that the group creation is the prerequisite step and the Permissions Management role is assigned to the group afterward. The comments collectively confirm that the first action is creating the security group, not assigning the product role directly to User1.Official Reference
Exam Strategy
When a Permissions Management question asks what to do first, think group-first: create a Microsoft Entra security group, then assign the Permissions Management role to that group. Direct role assignment to a user is a distractor because Permissions Management uses its own group-based access model.
Frequently Asked Questions
Why can't I assign a role directly to User1 for Permissions Management?
Permissions Management uses its own group-based access model; a direct user role assignment in Entra ID does not grant product access, so you must add the user to a security group first.
Does creating a security group really minimize administrative effort?
Yes, because you assign Permissions Management roles to the group once and then manage access by group membership, which is easier than repeating per-user role assignments as more users join.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →