SC-200 Manage a security operations environment Practice Question
Which TWO actions require the Global Administrator role in Microsoft 365?
⚠ Common exam trap
Test-takers frequently confuse 'tenant-wide settings' with workload-specific configurations, assuming that any security or compliance task requires Global Administrator, when in fact Microsoft has delegated many such tasks to specialized roles like Security Administrator or Compliance Administrator.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure tenant-wide settings in Microsoft 365
Configuring tenant-wide settings in Microsoft 365 requires the Global Administrator role because these settings affect the entire organization, including security, compliance, and user management. Only the Global Administrator has the broadest permissions to modify such high-level configurations, as defined by Microsoft's role-based access control (RBAC) model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a data loss prevention (DLP) policy in Microsoft Purview
Why it's wrong here
Creating a data loss prevention (DLP) policy in Microsoft Purview does not require the Global Administrator role; the Compliance Administrator role has sufficient permissions to create and manage DLP policies. DLP policies are scoped to the compliance and information protection administration area, so a user with Compliance Admin rights can define policy rules, conditions, and actions without broader tenant-wide administrative privileges.
- ✗
Create a custom role in Microsoft Defender XDR
Why it's wrong here
Creating a custom role in Microsoft Defender XDR falls under the Security Administrator role's responsibilities, not Global Admin. Security Administrators can define custom roles within the Defender RBAC model to grant granular permissions for threat protection features. This is a security-specific configuration that does not require the tenant-wide scope of Global Administrator.
- ✗
View the Microsoft 365 Defender incident queue
Why it's wrong here
Viewing the Microsoft 365 Defender incident queue is a read-only task that the Security Reader role is explicitly designed for. Security Readers have access to incident details, alerts, and threat analytics without needing the ability to modify settings. The Global Administrator role is not required to view incidents; it is a privileged role for changes, not for basic visibility.
- ✓
Configure tenant-wide settings in Microsoft 365
Why this is correct
Configuring tenant-wide settings in Microsoft 365 requires the Global Administrator role because these settings affect the entire organization, such as organizational profile, privacy preferences, and integration options. Only Global Administrators have the necessary authorization to modify settings that apply to all users and services across the tenant, ensuring central control and compliance with organizational governance.
- ✓
Manage roles and administrators in Microsoft Entra ID
Why this is correct
Managing roles and administrators in Microsoft Entra ID is a core Global Administrator function because it controls delegation of administrative permissions across the tenant. Only Global Administrators can assign privileged roles like Global Admin, Security Admin, or Compliance Admin to other users. This ensures that the ability to grant or revoke administrative access remains centralized and tightly controlled.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.