You are the global administrator for a company’s Azure subscription. The company uses Azure Active Directory
Premium and the Application Access Panel. You are configuring access to a Software as a Service (SaaS)
application.You need to ensure that the sales team lead is able to manage user access to the application but is unable to
modify administrative access to the application.
In the Azure portal, what should you do?
A.
Create an Azure group and assign it to the SaaS application. Create an Azure user with the User Admin
role, and assign the user as the owner of the new group.
B.
Create an Azure group and assign it to the SaaS application. Create an Azure user with the Service Admin
role, and assign the user as the owner of the new group.
C.
Set the values of the Delegated group management and Users can create groups settings to Enabled.
D.
Create an Azure group and assign it to the SaaS application. Create an Azure user with the Global Admin
role, and assign the user as the owner of the new group.
answer is C
Delegated group management An example is an administrator who is managing access to a SaaS application that the company is using. Managing these access rights is becoming cumbersome, so this administrator asks the business owner to create a new group. The administrator assigns access for the application to the new group, and adds to the group all people already accessing to the application. The business owner then can add more users, and those users are automatically provisioned to the application. The business owner doesn’t need to wait for the administrator to manage access for users. If the administrator grants the same permission to a manager in a different business group, then that person can also manage access for their own users. Neither the business owner nor the manager can view or manage each other’s users. The administrator can still see all users who have access to the application and block access rights if needed.
https://docs.microsoft.com/en-us/azure/active-directory/active-directory-accessmanagement-self-service-group-management#make-a-group-available-for-user-self-service
agreed with c