Least Privilege Permission to Onboard a Subscription to Permissions Management
You have a management group named Group1 that contains two Azure subscriptions named Sub1 and Sub2. The subscriptions are linked to a Microsoft Entra tenant that contains a user named User1. You need to ensure that User1 can onboard Sub1 to Permissions Management. The solution must follow the principle of least privilege. Which permission should you grant to User1?
Community Votes
60% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you know that onboarding a subscription to Permissions Management writes a role assignment and therefore requires roleAssignments/write at the subscription scope — not read, and not at management-group scope.
Onboarding an Azure subscription to Microsoft Entra Permissions Management creates a role assignment, so User1 needs Microsoft.Authorization/roleAssignments/write scoped to Sub1. This page confirms C as the least-privilege answer and explains why the subscription-scoped read permission (A) is insufficient.
Choosing A (Microsoft.Authorization/roleAssignments/read for Sub1) because the documentation says the Permissions Management app needs 'reader' permissions; that Reader grant is the result the onboarding operation produces, not the permission User1 needs to perform it.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Onboarding an Azure subscription to Microsoft Entra Permissions Management is an operation that creates a role assignment: the service grants its own app the Reader role at that subscription so it can collect data. Creating a role assignment requires Microsoft.Authorization/roleAssignments/write (the effective permission of Owner or User Access Administrator) at the target scope. Option C supplies exactly that permission on Sub1, the one subscription that must be onboarded, so no privilege spills over to Sub2. The missing dot in "MicrosoftAuthorization" is a formatting typo in the option text; the permission string and its scope — not its punctuation — determine the answer, which is why C is still the correct choice.Why the Other Options Are Wrong
A grants only Microsoft.Authorization/roleAssignments/read for Sub1, which lets User1 view existing assignments but not create the new one onboarding requires. YesPlease points to the docs' statement that the app "requires 'reader' permissions on the subscriptions", but that sentence describes the Reader role the onboarding process itself creates for the Permissions Management app, not what the operator must hold. B grants write at the Group1 management group, which also contains Sub2 — far broader than the task needs and a direct least-privilege violation. D is doubly wrong: read permission cannot onboard anything, and the management-group scope covers subscriptions User1 should not touch.Community Comment Notes
Votes split 60/40 between C and A, reflecting how the Reader wording in the onboarding article pulls learners toward A. d1e85d9 reasons that the task "requires role assignment permissions at the subscription level", which matches how the onboarding call actually behaves. Oskarma states simply that "The minimum priviledge level is at the subscription." YesPlease raises the observation that option C "is not even written in the right format", yet the intended write permission at subscription scope remains the least-privilege answer, so the typo does not change the verdict.Official Reference
Exam Strategy
When a 'least privilege' question offers the same permission at subscription scope and management-group scope, eliminate the management-group option first, then ask whether the task reads or writes. Onboarding always writes because it creates a role assignment, so select the write permission at the narrowest scope that still covers the target resource (Sub1).
Frequently Asked Questions
Why is roleAssignments/read on Sub1 (option A) not enough to onboard the subscription?
Onboarding creates a new role assignment granting the Permissions Management app Reader on Sub1, and creating an assignment requires write permission; read alone can only view existing assignments.
Why is roleAssignments/write on the management group (option B) wrong here?
Group1 also contains Sub2, so management-group scope would let User1 modify role assignments on a subscription that is not part of the onboarding task, breaking least privilege.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →