Which role can create access reviews for Microsoft Entra roles?

Plan, implement, and manage access reviews in Microsoft Entra Plan and implement privileged access
Answer Correct answer: D — Assign Privileged Role Administrator to User1 so they can create access reviews for Microsoft Entra role assignments with least privilege.

You have a Microsoft 365 E5 subscription that contains a user named User1. You need to ensure that User1 can create access reviews for Microsoft Entra roles. The solution must use the principle of least privilege. Which role should you assign to User1?

  1. Identity Governance Administrator
  2. User Access Administrator
  3. User Administrator
  4. Privileged Role Administrator Correct Answer

Community Votes

D
83%
A
17%

83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests scope-based access review permissions: Microsoft Entra role reviews require Privileged Role Administrator, while the common trap is assuming Identity Governance Administrator covers every access review type.

Creating access reviews for Microsoft Entra role assignments requires a role that can manage privileged directory role membership. This page establishes why Privileged Role Administrator (D) is the least-privilege answer, not Identity Governance Administrator, User Access Administrator, or User Administrator.

The most common wrong choice is Identity Governance Administrator, because its name suggests broad governance ownership, but it cannot create access reviews scoped to Microsoft Entra role assignments.

Community Discussion (4 comments)

anonymousarpanch 👍 1 Selected: D
To create access reviews for Microsoft Entra roles, you must be assigned at least the Privileged Role Administrator role. For access package it should be Identity governance administrator. For security groups, applications it should be Identity governance administrator. To create access reviews for Azure resources, you must be assigned to the Owner or the User Access Administrator role for the Azure resources.
JFROG 👍 1 Selected: D
If you look in https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#privileged-role-administrator The Privileged Role Administrator has hanage access reviews for Microsoft Entra role assignments. I don't see this with the Identity Governance Administrator (more groups etc). My choice is D.
Btn26 👍 1 Selected: A
The correct answer is A. Identity Governance Administrator Here's why: Identity Governance Administrator: This role provides the necessary permissions to manage identity governance tasks, including creating and managing access reviews for Microsoft Entra roles. User Access Administrator: This role provides permissions to manage user access within the organization, but it may not include the specific permissions to create access reviews for Entra roles. User Administrator: This role is primarily for managing user accounts and basic attributes, not for managing identity governance. Privileged Role Administrator: This role is for managing privileged roles within the organization, which is a broader scope than just creating access reviews
JinShi 👍 3 Selected: D
User Access Administrator role primarily focuses on managing user access

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Privileged Role Administrator is the narrowest built-in role that can create and manage access reviews for Microsoft Entra role assignments. Access reviews for directory roles govern privileged role membership, so the role must be able to read and manage role assignments in Microsoft Entra ID. As anonymousarpanch summarized, for Entra roles "you must be assigned at least the Privileged Role Administrator role." JFROG also pointed to the Microsoft permissions reference, where Privileged Role Administrator lists access reviews for Microsoft Entra role assignments. Assigning Global Administrator would also work, but it is broader and violates the least-privilege requirement.

Why the Other Options Are Wrong

Identity Governance Administrator can manage entitlement management, access packages, groups, and application access reviews, but it does not have the required permissions for Microsoft Entra role access reviews; anonymousarpanch noted, "For access package it should be Identity governance administrator." User Access Administrator manages user access to Azure resources and is not scoped to Entra directory role reviews, which matches JinShi's observation that it "primarily focuses on managing user access." User Administrator manages users, groups, and some helpdesk tasks, but it has no access-review authority over privileged Entra roles. Therefore none of A, B, or C satisfies both the task and least privilege.

Community Comment Notes

Most voters selected D, and the substantive comments explain the scope split rather than just echoing the key. Btn26 argued for Identity Governance Administrator, but that role's governance scope excludes Microsoft Entra role assignments. JFROG checked the official permissions reference and confirmed Privileged Role Administrator handles access reviews for Entra role assignments. JinShi and anonymousarpanch both highlighted that User Access Administrator and Identity Governance Administrator serve different scopes, reinforcing why D is the precise least-privilege role here.

Official Reference

Exam Strategy

Memorize the access review permission matrix by scope: Entra roles = Privileged Role Administrator; groups, apps, and access packages = Identity Governance Administrator; Azure resources = Owner or User Access Administrator. When least privilege is required, pick the narrowest role that explicitly lists the access-review task for the target object type.

Frequently Asked Questions

Why is Identity Governance Administrator wrong for Microsoft Entra role access reviews?

It can manage access reviews for groups, apps, and access packages, but it lacks permission to create access reviews scoped to Microsoft Entra directory role assignments.

Can Global Administrator create these access reviews?

Yes, but Global Administrator is broader than necessary; least privilege requires Privileged Role Administrator for this task.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide