Courseiva

AZ-500 Secure identity and access Practice Question

Which THREE Microsoft Entra ID roles can be assigned to a user to manage Microsoft Defender XDR (formerly Microsoft 365 Defender) incidents? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse the Security Reader role with the Security Operator role, or assume that Global Reader (which can view security settings) is sufficient to manage incidents, but only roles with write permissions like Security Administrator, Security Operator, or Global Administrator can actually manage Defender XDR incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Administrator

The Security Administrator role (Option B) can manage Microsoft Defender XDR incidents because it grants full access to security features, including the ability to view, investigate, and respond to incidents in the Microsoft 365 Defender portal. This role is designed for users who need to manage security policies and incidents without having full administrative control over the tenant.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exchange Administrator

    Why it's wrong here

    The Exchange Administrator role is scoped to Exchange Online management—mailboxes, recipient objects, and anti-phishing policies in Defender for Office 365—and does not grant permissions to the broader Microsoft 365 Defender security incident queue. It lacks the incident-response and security-policy update actions needed for managing alerts and incidents in Microsoft Entra ID or Defender for Cloud. Therefore, it cannot be the role assigned to a user responsible for security incident response.

  • ✓

    Security Administrator

    Why this is correct

    Security Administrator is a built-in Microsoft Entra ID role that grants permission to read security information, manage security policies, and act on security alerts and incidents in Microsoft 365 Defender, Defender for Cloud, and Identity Protection. It includes important actions such as managing conditional access policies, resetting passwords, and updating MFA settings, making it an appropriate role for incident response without granting full tenant-wide control. Because it supports day-to-day security administration and remediation, it is one of the roles that can be correctly assigned to a user.

  • ✗

    Global Reader

    Why it's wrong here

    Global Reader is a read-only directory role: it can view tenant configuration, service health, and security settings, but it cannot modify policies, dismiss alerts, or perform remediation actions in incident workflows. In the context of assigned security incident duties, a user with only Global Reader is an observer, not a responder, and therefore this role is not a valid choice for the question. The read-only scope makes it explicitly ineligible for managing incidents.

  • ✓

    Security Operator

    Why this is correct

    Security Operator is designed as a least-privilege security operations role; it can investigate, triage, and dismiss security alerts and incidents in Microsoft 365 Defender and Defender for Cloud, as well as manage detections and take limited remediation actions. Unlike Security Administrator, it intentionally cannot change security policy or configuration, but it is still assigned to users whose job is active incident response. This makes Security Operator one of the correct assignable roles for the scenario.

  • ✓

    Global Administrator

    Why this is correct

    Global Administrator has unrestricted access to all Microsoft Entra ID and Azure management capabilities, including every security center, alert, and incident-response workflow in the tenant. Because it implicitly contains the permissions of Security Administrator and Security Operator, a user assigned this role can manage incidents; however, it is overprivileged for routine security work and should be used only when no least-privilege role suffices. It is technically valid as an assignable role for the security incident scenario, so it is a correct answer.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.