お客様は、Microsoft Copilot for Security を使用する Microsoft 365 E5 サブスクリプションをご利用中です。Copilot for Security には既定の設定が構成されています。User1 という名前のユーザーが Copilot for Security を使用して次のタスクを実行できるようにする必要があります。
* ファイルをアップロードしてください。
* 利用状況ダッシュボードを表示します。
* プロンプトブックをすべてのユーザーと共有します。
解決策は最小権限の原則に従う必要があります。User1にはどの役割を割り当てるべきですか?
正解:D
In Microsoft Copilot for Security, permissions are governed by Copilot-specific roles. Copilot Owner is the role designed for administrative stewardship of a Copilot workspace and tenant-level features. According to Microsoft's role definitions, Owners can (1) view usage and billing/consumption dashboards , (2) manage promptbooks , including publishing and sharing promptbooks org-wide so they're available to all users, and (3) control data and session settings , which include allowing users to upload files during sessions.
These capabilities meet all three requirements with a single role and follow least privilege within Copilot's model because it is the lowest rol e that includes both usage visibility and tenant-wide sharing.
By contrast, Copilot Contributor can use Copilot, create prompts, upload files, and create promptbooks, but typically cannot view the usage dashboard and cannot publish/share promptbooks to "ev eryone" across the tenant. Traditional Entra roles such as Security Administrator or Cloud Application Administrator do not grant Copilot for Security workspace administration, usage insights, or promptbook publishing rights.
Therefore, to enable User1 to upload files, view the usage dashboard, and share promptbooks with all users- while using the minimal Copilot role that includes these abilities-the correct choice is Copilot Owner .