How to Replace a User's Azure Permissions with Read-Only in Permissions Management
You have an Azure subscription named Sub1 that uses Microsoft Entra Permissions Management. Sub1 contains a user named User1. User1 is granted multiple permissions across Sub1. You need to replace all the permissions granted to User1 with read-only permissions. The solution must minimize administrative effort. What should you do on the Remediation tab in Permissions Management?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you know the quick actions on the Remediation > Permissions subtab, not how to build roles or templates — the trap is over-engineering a one-off remediation into template or role creation.
On the Remediation tab of Microsoft Entra Permissions Management, the Permissions subtab exposes one-click quick actions, and 'Assign Read-Only Status' replaces every permission a user holds with read-only access. This page confirms that quick action (D) is the least-effort fix for User1's over-permissioned account in Sub1.
Choosing to create a role or a role/policy template, because it feels more 'proper'; but the goal is to replace all of one user's permissions with read-only with minimal administrative effort, which only the built-in quick action does in a single click.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The Remediation tab in Microsoft Entra Permissions Management groups finding-driven actions, and its Permissions subtab offers ready-made quick actions — including Assign Read-Only Status — that rewrite a user's effective permissions to read-only in one operation. Because User1 holds multiple permissions scattered across Sub1, a single quick action is the only option that satisfies both the outcome (all permissions become read-only) and the requirement to minimize administrative effort. Saynot enumerated the four quick actions and listed "Assign Read-Only Status" as the one that fits, and razit pointed to the Microsoft Learn walkthrough billed as "Right-sizing access with the click of a button." Panama469 added that the referenced documentation shows "an image of that exact scenario," confirming the question was lifted from that flow. No other option performs an in-place replacement of an existing user's permission set.Why the Other Options Are Wrong
Creating a template from the Role/Policy Template subtab (A) builds a reusable definition for future onboarding or bulk remediation; it does not itself strip User1's current permissions, so extra steps remain. Creating a new request from My Requests (B) is the workflow for requesting or approving access — the opposite of removing it — and would leave the existing grants intact. Creating a role from the Roles/Policies subtab (C) defines a custom role object, but a role is inert until assigned, and you would still have to revoke every prior grant, which multiplies effort. Only the quick action on the Permissions subtab both adds the read-only outcome and removes the existing permissions in one action.Community Comment Notes
Community sentiment is effectively unanimous: Saynot and dzdz confirmed D by listing the quick actions and noting that no template, request, or role needs to be created, and both cited the Microsoft Learn remediation-tab page. Panama469 endorsed it, and razit linked the same page under the heading about right-sizing access "with the click of a button." Sneekygeek was the lone voice for C, reasoning from the same documentation page, but a newly created role still has to be assigned and the old grants revoked — it does not replace permissions by itself, so that reading does not survive the 'minimize administrative effort' requirement.Official Reference
Exam Strategy
When an SC-300 item says 'minimize administrative effort' and names a Permissions Management subtab, look for the built-in quick action rather than a build-it-yourself role or template. Memorize the four quick actions — Revoke Unused Tasks, Revoke High-Risk Tasks, Revoke Delete Tasks, and Assign Read-Only Status — so the subtab names in the distractors cannot mislead you.
Frequently Asked Questions
Why is creating a role from the Roles/Policies subtab wrong for making User1 read-only?
Creating a role only defines a custom role object; you would still have to assign it and revoke every existing permission, which adds work instead of minimizing it.
Which quick action on the Permissions subtab replaces a user's permissions with read-only?
Assign Read-Only Status. It is one of four quick actions alongside Revoke Unused, Revoke High-Risk, and Revoke Delete Tasks, and it changes a user's access in a single click.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →