How to Replace a User's Azure Permissions with Read-Only in Permissions Management

Plan and implement privileged access Monitor identity activity by using logs, workbooks, and reports
Answer Correct answer: D — On the Remediation tab, use a quick action on the Permissions subtab to assign read-only status to User1.

You have an Azure subscription named Sub1 that uses Microsoft Entra Permissions Management. Sub1 contains a user named User1. User1 is granted multiple permissions across Sub1. You need to replace all the permissions granted to User1 with read-only permissions. The solution must minimize administrative effort. What should you do on the Remediation tab in Permissions Management?

  1. From the Role/Policy Template subtab, create a template.
  2. From the My Requests subtab, create a new request.
  3. From the Roles/Policies subtab, create a role.
  4. From the Permissions subtab, use a quick action. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you know the quick actions on the Remediation > Permissions subtab, not how to build roles or templates — the trap is over-engineering a one-off remediation into template or role creation.

On the Remediation tab of Microsoft Entra Permissions Management, the Permissions subtab exposes one-click quick actions, and 'Assign Read-Only Status' replaces every permission a user holds with read-only access. This page confirms that quick action (D) is the least-effort fix for User1's over-permissioned account in Sub1.

Choosing to create a role or a role/policy template, because it feels more 'proper'; but the goal is to replace all of one user's permissions with read-only with minimal administrative effort, which only the built-in quick action does in a single click.

Community Discussion (5 comments)

Saynot 👍 13 Selected: D
There are four quick actions that can be used to manage users: Revoke Unused Tasks Revoke High-Risk Tasks Revoke Delete Tasks Assign Read-Only Status https://learn.microsoft.com/en-us/training/permissions-management/explore-features-of-permissions-management/9-act-on-your-findings-with-remediation-tab
Panama469 👍 3 Selected: D
Agree, the links below show an image of that exact scenario.
dzdz 👍 4
D. From the Permissions subtab, use a quick action. On the Remediation tab in Microsoft Entra Permissions Management, you would use a quick action from the Permissions subtab to replace all the permissions granted to User1 with read-only permissions. This approach allows for quick and efficient modification of permissions without the need to create new templates, requests, or roles. Using a quick action from the Permissions subtab would minimize administrative effort while achieving the desired outcome of granting read-only permissions to User1.
razit 👍 3 Selected: D
See Right-sizing access with the click of a button at: https://learn.microsoft.com/en-us/training/permissions-management/explore-features-of-permissions-management/9-act-on-your-findings-with-remediation-tab
Sneekygeek 👍 1 Selected: C
C Seems Correct based on this: https://learn.microsoft.com/en-us/training/permissions-management/explore-features-of-permissions-management/9-act-on-your-findings-with-remediation-tab

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Remediation tab in Microsoft Entra Permissions Management groups finding-driven actions, and its Permissions subtab offers ready-made quick actions — including Assign Read-Only Status — that rewrite a user's effective permissions to read-only in one operation. Because User1 holds multiple permissions scattered across Sub1, a single quick action is the only option that satisfies both the outcome (all permissions become read-only) and the requirement to minimize administrative effort. Saynot enumerated the four quick actions and listed "Assign Read-Only Status" as the one that fits, and razit pointed to the Microsoft Learn walkthrough billed as "Right-sizing access with the click of a button." Panama469 added that the referenced documentation shows "an image of that exact scenario," confirming the question was lifted from that flow. No other option performs an in-place replacement of an existing user's permission set.

Why the Other Options Are Wrong

Creating a template from the Role/Policy Template subtab (A) builds a reusable definition for future onboarding or bulk remediation; it does not itself strip User1's current permissions, so extra steps remain. Creating a new request from My Requests (B) is the workflow for requesting or approving access — the opposite of removing it — and would leave the existing grants intact. Creating a role from the Roles/Policies subtab (C) defines a custom role object, but a role is inert until assigned, and you would still have to revoke every prior grant, which multiplies effort. Only the quick action on the Permissions subtab both adds the read-only outcome and removes the existing permissions in one action.

Community Comment Notes

Community sentiment is effectively unanimous: Saynot and dzdz confirmed D by listing the quick actions and noting that no template, request, or role needs to be created, and both cited the Microsoft Learn remediation-tab page. Panama469 endorsed it, and razit linked the same page under the heading about right-sizing access "with the click of a button." Sneekygeek was the lone voice for C, reasoning from the same documentation page, but a newly created role still has to be assigned and the old grants revoked — it does not replace permissions by itself, so that reading does not survive the 'minimize administrative effort' requirement.

Official Reference

Exam Strategy

When an SC-300 item says 'minimize administrative effort' and names a Permissions Management subtab, look for the built-in quick action rather than a build-it-yourself role or template. Memorize the four quick actions — Revoke Unused Tasks, Revoke High-Risk Tasks, Revoke Delete Tasks, and Assign Read-Only Status — so the subtab names in the distractors cannot mislead you.

Frequently Asked Questions

Why is creating a role from the Roles/Policies subtab wrong for making User1 read-only?

Creating a role only defines a custom role object; you would still have to assign it and revoke every existing permission, which adds work instead of minimizing it.

Which quick action on the Permissions subtab replaces a user's permissions with read-only?

Assign Read-Only Status. It is one of four quick actions alongside Revoke Unused, Revoke High-Risk, and Revoke Delete Tasks, and it changes a user's access in a single click.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide