Which role for the Permissions Management service principal?

Plan and implement privileged access Plan and implement identities for applications and Azure workloads
Answer Correct answer: A — Assign the User Access Administrator role to the Permissions Management service principal so it can create and assign right-sized roles.

You have an Azure subscription. You need to use Microsoft Entra Permissions Management to automatically monitor permissions and create and implement right-size roles. The solution must follow the principle of least privilege. Which role should you assign to the service principal of Permissions Management?

  1. User Access Administrator Correct Answer
  2. Contributor
  3. Reader
  4. Owner

Community Votes

A
67%
B
33%

67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the boundary between roles that manage Azure resources and roles that manage access to those resources — the trap is assuming Contributor, which can change resources, can also create and assign the right-sized roles Permissions Management produces.

The Azure RBAC role you assign to the Microsoft Entra Permissions Management service principal decides whether the tool can both monitor permissions and act on its right-sizing recommendations. This page establishes that User Access Administrator (A) is the least-privileged built-in role that satisfies both requirements.

Most candidates choose Contributor (B) because Permissions Management 'creates and implements' changes, but Contributor has no Microsoft.Authorization permissions, so it can neither author role definitions nor assign roles; Reader (C) fails for the opposite reason and Owner (D) breaks least privilege.

Community Discussion (7 comments)

dzdz 👍 12
A. User Access Administrator To use Microsoft Entra Permissions Management to automatically monitor permissions and create and implement right-size roles while following the principle of least privilege, you should assign the User Access Administrator role to the service principal of Permissions Management. The User Access Administrator role allows the service principal to manage user access to Azure resources, including the ability to grant and revoke access, but it does not grant excessive permissions such as Contributor or Owner roles. This aligns with the principle of least privilege, ensuring that the service principal has the necessary permissions to perform its tasks without unnecessary access to modify resources.
rvln7 👍 1 Selected: D
User Access Administrator can manage permissions but cannot modify resources. Since Permissions Management also needs to create and assign right-sized roles, this role is not sufficient. Since Microsoft Entra Permissions Management needs the ability to both analyze and modify permissions, Owner is the most appropriate role for its service principal. its about service principal permissions that application has, not about the user (human) permissions needed to manage portal e.g.
Matt19 👍 1 Selected: A
For least privileged role it should be User access Administrator
ProNerd 👍 1 Selected: A
needs access to create the roles, so it's user access admin
Labelfree 👍 4 Selected: A
Can some of you guys saying A? Hit the voting comment here and select that answer. Nobody has answered that yet, but -- that's the correct answer. Why User Access Administrator is the Correct Role: User Access Administrator allows the service principal to manage permissions for Azure resources, including creating and assigning roles and managing access. This role provides sufficient privileges to monitor permissions and implement the right-sizing of roles in alignment with the least privilege principle. User Administrator allows for the creation of custom roles, role assignments, and the ability to configure access management, which is essential for what is asked here. you can create and manage resources with Contributor but not permissions.
martutene 👍 1 Selected: C
It's reader, appears on John Christopher's video. Then the user that uses the service needs a role that can do that, but to read info from the cloud providers in azure is the reader role.
jarattdavis 👍 3 Selected: B
Correct Answer B: To use Microsoft Entra Permissions Management to automatically monitor permissions and create and implement right-size roles while following the principle of least privilege, you should assign the Contributor role to the service principal12. This role provides the necessary permissions to manage resources without granting full administrative access.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

User Access Administrator is the only role in the option set that grants Microsoft.Authorization//read together with Microsoft.Authorization/roleAssignments/ and Microsoft.Authorization/roleDefinitions/*, which map exactly to what the service principal must do: read current assignments and then create and apply right-sized roles. The question's phrase "create and implement right-size roles" requires write on role definitions and role assignments, not merely visibility. Because User Access Administrator carries no write permissions over the resources themselves, it satisfies the explicit principle of least privilege while still enabling remediation. Community voters reached the same conclusion, with ProNerd summarizing it as "needs access to create the roles, so it's user access admin" and Labelfree calling it "the Correct Role". Assigning Owner would work functionally but grants full control at subscription scope, which the requirement rules out.

Why the Other Options Are Wrong

Contributor (B) lets the principal manage Azure resources but deliberately excludes Microsoft.Authorization write, so Permissions Management could detect an over-privileged assignment yet be unable to create or assign the replacement role — jarattdavis argued for B but conflates resource management with access management. Reader (C) is even more restrictive: it can collect data, which is why monitoring-only deployments use it, but it cannot implement any change, so "right-size roles" would be impossible. Owner (D) covers every operation but also allows arbitrary resource deletion and role escalation, directly contradicting least privilege. Between the four, only User Access Administrator hits the exact permission surface the task describes.

Community Comment Notes

dzdz's highly rated answer walks through the same reasoning and is the strongest community justification for A. Labelfree urges voters to commit to A, noting that User Access Administrator "allows the service principal to manage permissions for Azure resources". ProNerd adds the concise rationale "needs access to create the roles, so it's user access admin". rvln7 argues for Owner because "User Access Administrator can manage permissions but cannot modify resources" — a misunderstanding, since right-sizing changes role assignments rather than resource configuration. martutene cites a video for Reader ("It's reader, appears on John Christopher's video"), which is valid only if Permissions Management is used for visibility alone.

Official Reference

Exam Strategy

When a question says 'create and implement roles' or 'manage access', filter the options by the Microsoft.Authorization permission family rather than by general resource control. Reader = read everything but change nothing; Contributor = change resources but not access; User Access Administrator = change access but not resources; Owner = both, hence never least privilege.

Frequently Asked Questions

Why is Contributor (B) not enough for the Permissions Management service principal?

Contributor can manage Azure resources but has no Microsoft.Authorization permissions, so it cannot create the custom role definitions or assign the right-sized roles Permissions Management generates.

Does the service principal also need Reader on the subscription?

User Access Administrator already includes Microsoft.Authorization/*/read, so role assignments and role definitions can be read. Reader alone is insufficient because it cannot implement any role change.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide