SC-300 Exam QuestionsBrowse all questions from this exam

SC-300 Exam - Question 306


You have an Azure AD tenant that contains two users named User1 and User2.

You plan to perform the following actions:

• Create a group named Group1.

• Add User1 and User2 to Group1.

• Assign Azure AD roles to Group1.

You need to create Group1.

Which two settings can you use? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

Show Answer
Correct Answer: AB

To create a group in Azure AD that can have Azure AD roles assigned to it, you need to ensure that the group type and membership type are compatible with this feature. You can use either a Microsoft 365 group with an assigned membership type or a Security group with an assigned membership type. Dynamic membership types are not suitable for assigning Azure AD roles as it could lead to unintended elevation of permissions based on dynamic attributes.

Discussion

7 comments
Sign in to comment
BRoald
Jan 19, 2023

Correct, when you create a group you MUST enable "azure ad roles can be assigned to the group" (cannot be done afterwards). If you enable this feature when creating a group, dynamic groups are getting greyed out / disabled. So yes, only assigned security and assigned m365 groups

Zak366
Feb 24, 2023

Just confirmed on my tenant

dule27Options: AB
Jun 30, 2023

A. Group type: Microsoft 365 - Membership type: Assigned B. Group type: Security - Membership type: Assigned

Discuss4certiOptions: AB
Jul 5, 2024

correct and logical. Any dynamic group would be able to give you elevated permissions just because you changed a certain attribute? that would defeat the whole purpose of using PIM.

AAsif098Options: AB
Feb 14, 2023

Correct - Tested and when you select either M365 Group as Group type or Security, the default Assignment Type is "Assigned" This can't be changed

EmnCoursOptions: AB
Jul 28, 2023

A. Group type: Microsoft 365 - Membership type: Assigned B. Group type: Security - Membership type: Assigned

haazybanjOptions: AB
Oct 28, 2023

A. Group type: Microsoft 365 - Membership type: Assigned B. Group type: Security - Membership type: Assigned

Obi_Wan_JacobyOptions: AB
May 5, 2025

Answer: AB is correct