Question 1
You have an Azure subscription that contains a user named User1. The subscription is onboarded to Microsoft Entra Permissions Management. You need to provide User! with access to Permissions Management. The solution must meet the following requirements:
* Follow the principle of least privilege.
* Minimize administrative effort.
What should you do first?
When onboarding to Microsoft Entra Permissions Management (a CIEM solution), before a user can perform any functions inside Permissions Management, that user must be granted an appropriate Permissions Management role in the Entra tenant. The principle of least privilege dictates that you grant only the minimal role necessary (for example, a Permissions Management Approver, Viewer, or Controller). The SC-300 study materials and Microsoft's documentation emphasize that administrative access must begin by assigning roles within Entra ID.
Creating a security group (option A) is a useful organizational practice but doesn't itself grant the user permissions inside Permissions Management. Creating a role/policy template (option B) is about defining permission scopes and is not a first step to allow a user access. Creating a request in My Requests (option D) presupposes that User1 already has some entitlement to make requests (i.e. some role), which they don't yet.
Therefore, the first action is to assign a Permissions Management role to User1 from the Entra admin center, thus giving them appropriate access while adhering to least privilege.

