MS-102 Exam QuestionsBrowse all questions from this exam

MS-102 Exam - Question 124


HOTSPOT

-

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

Exam MS-102 Question 124

You are implementing Microsoft Defender for Endpoint.

You need to enable role-based access control (RBAC) to restrict access to the Microsoft 365 Defender portal.

Which users can enable RBAC, and which users will no longer have access to the Microsoft 365 Defender portal after RBAC is enabled? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Exam MS-102 Question 124
Show Answer
Correct Answer:
Exam MS-102 Question 124

Discussion

8 comments
Sign in to comment
cb0900
Sep 12, 2023

Agree with the answers. Enable RBAC: Admin1 and Admin 2 No longer have access: Admin 3 and Admin 4 Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Azure AD Security reader role) to lose access until they are assigned to a role. https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide#before-you-begin https://www.examtopics.com/discussions/microsoft/view/110910-exam-ms-101-topic-2-question-138-discussion/

imlearningstuffagain
Oct 24, 2023

this is nice wording, the Application Administrator didn't have access to begin with. So he/she doesn't lose access. Correct?

nils241
Jan 2, 2024

Users with "Application Administor Role" can only create and manage all aspects of enterprise applications, application registrations, and application proxy settings.

sergioandreslq
Nov 13, 2023

Initially, only those with Microsoft Entra Global Administrator or Security Administrator rights will be able to create and assign roles in the Microsoft 365 Defender portal https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide#before-you-begin

nils241
Jan 2, 2024

Users with "Application Administor Role" can only create and manage all aspects of enterprise applications, application registrations, and application proxy settings.

m2L
Dec 21, 2023

NO2 : Admin3, Admin4, Admin5

Tomtom11
Feb 21, 2024

https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/rbac?view=o365-worldwide Initially, only those with Microsoft Entra Global Administrator or Security Administrator rights will be able to create and assign roles in the Microsoft Defender portal, therefore, having the right groups ready in Microsoft Entra ID is important. Turning on role-based access control will cause users with read-only permissions (for example, users assigned to Microsoft Entra Security reader role) to lose access until they are assigned to a role. Users with admin permissions are automatically assigned the default built-in Defender for Endpoint global administrator role with full permissions. After opting in to use RBAC, you can assign additional users that are not Microsoft Entra Global or Security Administrators to the Defender for Endpoint global administrator role. After opting in to use RBAC, you cannot revert to the initial roles as when you first logged into the portal.

Jamesat
Apr 29, 2024

Agreed. After enabling RBAC only Global Admin and Security Admin will have access so Admin 1 and Admin 2 is correct. For the second question it is Admin 3 and Admin 4. The question is Users that will NO LONGER have access. The Application Admin never had access so shouldn't be included.

Murad01
Jun 28, 2024

Given answer are correct

jarattdavis
Aug 21, 2024

= Admin1 and Admin2 can enable RBAC because they have the highest-level administrative privileges (Global Administrator and Security Administrator). = Admin3, Admin4, and Admin5 will lose access to the Microsoft 365 Defender portal after RBAC is enabled. This is because they have roles that are typically granted limited or read-only access, and RBAC allows for granular control over permissions.

APK1
Aug 22, 2024

Given answer is correct. For the second question here is the key point in the question "Users that will NO LONGER have access" - The Application Admin never had access so shouldn't be included.

Frank_2022
Apr 16, 2025

Users who can enable RBAC: Admin1 (Global Admin) Admin2 (Security Admin) Users who will lose access after RBAC is enabled: Admin3 (Security Operator) Admin4 (Security Reader) Admin5 (Application Admin)