Forum Discussion
Fazil_RF
Sep 30, 2021Copper Contributor
Need answer for Az-104 Q&A please
Can I've an answer for the below question with good explanation. You have an Azure subscription that contains a user account named User1. You need to ensure that User1 can assign a policy to the te...
jpa210
Oct 29, 2024Copper Contributor
Fazil_RF Can't be A or D because if user1 is the owner of the subscription he can do anything inside it, but he cannot have access to the tenant root management group, because it is a superior level in the hierarachy. Azure AD Global Administrators are the only users that can elevate themselves to gain access. Once they have access to the root management group, the global administrators can assign any Azure role to other users to manage it.
- joaopedro11460Nov 04, 2024Copper Contributor
After reading the response of another person I though about mine, and I reconsider, and agree that A is the right answer. I was wrongly assuming that user1 was owner at subscription level, but this is not siad in the answer, so he can be assigned owner role at the tenant root management group level, and be able to assign policies afterwards.