A support team must be able to view every resource in a subscription, including anything created next month, and must not be able to change anything. Which assignment is correct?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct Assign the built-in Reader role to the support team's group at the subscription scope

Correct. Assignments are inherited by everything beneath the scope, so future resource groups and resources are covered without further action, and Reader is view-only by definition.

Not correct Assign the Contributor role to the group at the subscription scope

Wrong. Contributor can create, modify and delete resources, which fails the second half of the requirement outright. Contributor is the role people reach for when Reader would have done.

Not correct Assign Reader to each team member individually on each existing resource

Wrong on two counts: it misses everything created afterwards, and it multiplies assignments that then have to be maintained per person. Assign to groups, at the highest scope where the statement is true.

Not correct Assign the Owner role at the resource group scope

Wrong twice. Owner adds the ability to grant access to other people on top of full control, and a resource group scope covers only part of the subscription.

Why

A role assignment is three things: a principal, a role definition, and a scope — management group, subscription, resource group or a single resource — and it flows downward from wherever you make it. That inheritance is the tool: assign at the highest scope where the sentence you are enforcing is still true, to a group rather than to people, using the least privileged built-in role that covers the need. Reader views, Contributor changes, Owner changes and also grants access.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services