Which role for the Permissions Management service principal?
You have an Azure subscription. You need to use Microsoft Entra Permissions Management to automatically monitor permissions and create and implement right-size roles. The solution must follow the principle of least privilege. Which role should you assign to the service principal of Permissions Management?
Community Votes
67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the boundary between roles that manage Azure resources and roles that manage access to those resources — the trap is assuming Contributor, which can change resources, can also create and assign the right-sized roles Permissions Management produces.
The Azure RBAC role you assign to the Microsoft Entra Permissions Management service principal decides whether the tool can both monitor permissions and act on its right-sizing recommendations. This page establishes that User Access Administrator (A) is the least-privileged built-in role that satisfies both requirements.
Most candidates choose Contributor (B) because Permissions Management 'creates and implements' changes, but Contributor has no Microsoft.Authorization permissions, so it can neither author role definitions nor assign roles; Reader (C) fails for the opposite reason and Owner (D) breaks least privilege.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
User Access Administrator is the only role in the option set that grants Microsoft.Authorization//read together with Microsoft.Authorization/roleAssignments/ and Microsoft.Authorization/roleDefinitions/*, which map exactly to what the service principal must do: read current assignments and then create and apply right-sized roles. The question's phrase "create and implement right-size roles" requires write on role definitions and role assignments, not merely visibility. Because User Access Administrator carries no write permissions over the resources themselves, it satisfies the explicit principle of least privilege while still enabling remediation. Community voters reached the same conclusion, with ProNerd summarizing it as "needs access to create the roles, so it's user access admin" and Labelfree calling it "the Correct Role". Assigning Owner would work functionally but grants full control at subscription scope, which the requirement rules out.Why the Other Options Are Wrong
Contributor (B) lets the principal manage Azure resources but deliberately excludes Microsoft.Authorization write, so Permissions Management could detect an over-privileged assignment yet be unable to create or assign the replacement role — jarattdavis argued for B but conflates resource management with access management. Reader (C) is even more restrictive: it can collect data, which is why monitoring-only deployments use it, but it cannot implement any change, so "right-size roles" would be impossible. Owner (D) covers every operation but also allows arbitrary resource deletion and role escalation, directly contradicting least privilege. Between the four, only User Access Administrator hits the exact permission surface the task describes.Community Comment Notes
dzdz's highly rated answer walks through the same reasoning and is the strongest community justification for A. Labelfree urges voters to commit to A, noting that User Access Administrator "allows the service principal to manage permissions for Azure resources". ProNerd adds the concise rationale "needs access to create the roles, so it's user access admin". rvln7 argues for Owner because "User Access Administrator can manage permissions but cannot modify resources" — a misunderstanding, since right-sizing changes role assignments rather than resource configuration. martutene cites a video for Reader ("It's reader, appears on John Christopher's video"), which is valid only if Permissions Management is used for visibility alone.Official Reference
Exam Strategy
When a question says 'create and implement roles' or 'manage access', filter the options by the Microsoft.Authorization permission family rather than by general resource control. Reader = read everything but change nothing; Contributor = change resources but not access; User Access Administrator = change access but not resources; Owner = both, hence never least privilege.
Frequently Asked Questions
Why is Contributor (B) not enough for the Permissions Management service principal?
Contributor can manage Azure resources but has no Microsoft.Authorization permissions, so it cannot create the custom role definitions or assign the right-sized roles Permissions Management generates.
Does the service principal also need Reader on the subscription?
User Access Administrator already includes Microsoft.Authorization/*/read, so role assignments and role definitions can be read. Reader alone is insufficient because it cannot implement any role change.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →