Least Privilege Permission to Onboard a Subscription to Permissions Management

Manage and monitor app access by using Microsoft Defender for Cloud Apps
Answer Correct answer: C — Grant User1 Microsoft.Authorization/roleAssignments/write on Sub1, the least-privilege permission needed to onboard Sub1 to Permissions Management.

You have a management group named Group1 that contains two Azure subscriptions named Sub1 and Sub2. The subscriptions are linked to a Microsoft Entra tenant that contains a user named User1. You need to ensure that User1 can onboard Sub1 to Permissions Management. The solution must follow the principle of least privilege. Which permission should you grant to User1?

  1. Microsoft.Authorization/roleAssignments/read for Sub1
  2. Microsoft.Authorization/roleAssignments/write for Group1
  3. MicrosoftAuthorization/roleAssignments/write for Sub1 Correct Answer
  4. Microsoft.Authorization/roleAssignments/read for Group1

Community Votes

C
60%
A
40%

60% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you know that onboarding a subscription to Permissions Management writes a role assignment and therefore requires roleAssignments/write at the subscription scope — not read, and not at management-group scope.

Onboarding an Azure subscription to Microsoft Entra Permissions Management creates a role assignment, so User1 needs Microsoft.Authorization/roleAssignments/write scoped to Sub1. This page confirms C as the least-privilege answer and explains why the subscription-scoped read permission (A) is insufficient.

Choosing A (Microsoft.Authorization/roleAssignments/read for Sub1) because the documentation says the Permissions Management app needs 'reader' permissions; that Reader grant is the result the onboarding operation produces, not the permission User1 needs to perform it.

Community Discussion (3 comments)

d1e85d9 👍 1 Selected: C
In this scenario, User1 needs to onboard Sub1 to Permissions Management. This requires role assignment permissions at the subscription level. Analysis of Options: Correct Answer: C. Microsoft.Authorization/roleAssignments/write for Sub1 This permission grants User1 the necessary write access at the subscription level to onboard Sub1 to Permissions Management while adhering to the principle of least privilege.
YesPlease 👍 2 Selected: A
Answer A) Least permission is on SUB1. Microsoft.Authorization/roleAssignments/read for Sub1 "C" is not even written in the right format https://learn.microsoft.com/en-us/entra/permissions-management/onboard-azure#explanation:~:text=This%20app%20requires%20%27reader%27%20permissions%20on%20the%20subscriptions
Oskarma 👍 2 Selected: C
The minimum priviledge level is at the subscription.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Onboarding an Azure subscription to Microsoft Entra Permissions Management is an operation that creates a role assignment: the service grants its own app the Reader role at that subscription so it can collect data. Creating a role assignment requires Microsoft.Authorization/roleAssignments/write (the effective permission of Owner or User Access Administrator) at the target scope. Option C supplies exactly that permission on Sub1, the one subscription that must be onboarded, so no privilege spills over to Sub2. The missing dot in "MicrosoftAuthorization" is a formatting typo in the option text; the permission string and its scope — not its punctuation — determine the answer, which is why C is still the correct choice.

Why the Other Options Are Wrong

A grants only Microsoft.Authorization/roleAssignments/read for Sub1, which lets User1 view existing assignments but not create the new one onboarding requires. YesPlease points to the docs' statement that the app "requires 'reader' permissions on the subscriptions", but that sentence describes the Reader role the onboarding process itself creates for the Permissions Management app, not what the operator must hold. B grants write at the Group1 management group, which also contains Sub2 — far broader than the task needs and a direct least-privilege violation. D is doubly wrong: read permission cannot onboard anything, and the management-group scope covers subscriptions User1 should not touch.

Community Comment Notes

Votes split 60/40 between C and A, reflecting how the Reader wording in the onboarding article pulls learners toward A. d1e85d9 reasons that the task "requires role assignment permissions at the subscription level", which matches how the onboarding call actually behaves. Oskarma states simply that "The minimum priviledge level is at the subscription." YesPlease raises the observation that option C "is not even written in the right format", yet the intended write permission at subscription scope remains the least-privilege answer, so the typo does not change the verdict.

Official Reference

Exam Strategy

When a 'least privilege' question offers the same permission at subscription scope and management-group scope, eliminate the management-group option first, then ask whether the task reads or writes. Onboarding always writes because it creates a role assignment, so select the write permission at the narrowest scope that still covers the target resource (Sub1).

Frequently Asked Questions

Why is roleAssignments/read on Sub1 (option A) not enough to onboard the subscription?

Onboarding creates a new role assignment granting the Permissions Management app Reader on Sub1, and creating an assignment requires write permission; read alone can only view existing assignments.

Why is roleAssignments/write on the management group (option B) wrong here?

Group1 also contains Sub2, so management-group scope would let User1 modify role assignments on a subscription that is not part of the onboarding task, breaking least privilege.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide