As your organization’s administrator, you want to assign a delegated admin custom role in order to perform a limited set of ChromeOS device management tasks only for the Marketing organizational unit. What should you do?
A.
Create and assign a super admin role
B.
Create and assign a custom role with "Chrome Management permissions" for the root OU
C.
Create and assign a custom role with "Chrome Management permissions" for the Marketing devices OU
D.
Create and assign a custom role with "Chrome Management permissions" for the Marketing Users OU
To delegate ChromeOS device management specifically for theMarketing OU, create acustom rolewith"Chrome Management permissions"and assign it specifically to theMarketing devices OU. This ensures that the delegated admin can manage only the devices within that specific OU without impacting the entire organization.
Verified Answer from Official Source:
The correct answer is verified from theGoogle Admin Console Role Management Guide, which recommends assigning roles at the appropriate OU level for granular access control.
"Assign roles to specific OUs to limit administrative control to relevant organizational units, such as the Marketing devices OU."
By targeting the role to the Marketing devices OU, you ensure that the delegated admin does not have unnecessary access to devices in other parts of the organization, maintaining the principle of least privilege.
Objectives:
Implement delegated administration for specific OUs.
Limit administrative scope to enhance security.
[References:, Google Admin Console Role Management Guide, ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit