You are on page 1of 1

Your network contains an active directory domain services(AD DS) domain named contoso.

com
and an Azure Active Directory(Azure AD) domain named contoso.onmicrosoft.com. you are
using role based Access Control(RBAC) policies to control who has rights within the azure
subscription.You are a global administrator,and have the "owner" built-in role. A member of
your team named Mary should be allowed to create and manage all objects in the
subscription,but should not be able to add or remove role assignments. you need to give Mary
only the rights that she needs. This must be accomplished with the least amount of
administrative effort.what should you do?
A. Add Mary to the Reader Role
B. Add Mary to the Owner Role.
C. Create a custom RBAC role for Mary.
D. Add Mary to the contributor role correct.

You might also like