exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 99 discussion

Actual exam question from Microsoft's AZ-500
Question #: 99
Topic #: 2
[All AZ-500 Questions]

You have an Azure subscription that contains a user named User1.

You need to ensure that User1 can perform the following tasks:

• Create groups.
• Create access reviews for role-assignable groups.
• Assign Azure AD roles to groups.

The solution must use the principle of least privilege.

Which role should you assign to User1?

  • A. Groups administrator
  • B. Authentication administrator
  • C. Identity Governance Administrator
  • D. Privileged role administrator
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
golitech
2 months, 4 weeks ago
Selected Answer: A
B,C,D cannot create groups
upvoted 1 times
...
MohCert
8 months, 3 weeks ago
Selected Answer: D
Answer is D https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#privileged-role-administrator None of the other three roles has the privileges to perform ALL mentioned tasks https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#identity-governance-administrator https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#authentication-administrator https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#groups-administrator
upvoted 3 times
...
cris_exam
9 months, 1 week ago
Selected Answer: D
tested and Privileged Role Admin was able to perform all required tasks.
upvoted 1 times
...
ndv4461
10 months, 2 weeks ago
I think D is the correct answer.
upvoted 1 times
...
Obama_boy
10 months, 3 weeks ago
Selected Answer: C
C. Identity Governance Administrator The Identity Governance Administrator role in Azure AD is designed for managing identity governance features, including access reviews, entitlement management, and privileged identity management. This role allows a user to create and manage access reviews, which are used to govern group memberships and role assignments, including Azure AD roles for role-assignable groups. Assigning User1 the Identity Governance Administrator role would allow them to perform the tasks mentioned (creating groups, creating access reviews for role-assignable groups, and assigning Azure AD roles to groups) while adhering to the principle of least privilege, as this role is specifically focused on governance features and does not grant broader administrative rights that are not necessary for the tasks.
upvoted 1 times
yonie
10 months, 1 week ago
Doesnt seem to have permission to create groups or assign roles. It is focused only on access reviews.
upvoted 1 times
...
...
wardy1983
11 months, 2 weeks ago
Answer: D Explanation: D : Users with this role can manage role assignments in Azure Active Directory, as well as within Azure AD Privileged Identity Management. They can create and manage groups that can be assigned to Azure AD roles. In addition, this role allows management of all aspects of Privileged Identity Management and administrative units.Under Action you'll find :microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create >>Create access reviews for membership in groups that are assignable to Azure AD roles https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#privileged-roleadministrator
upvoted 1 times
...
alfaAzure
1 year, 2 months ago
Selected Answer: D
D is correct. https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#privileged-role-administrator
upvoted 3 times
...
ESAJRR
1 year, 2 months ago
Selected Answer: D
D. Privileged role administrator
upvoted 1 times
alfaAzure
1 year, 2 months ago
Correct D. https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#privileged-role-administrator
upvoted 1 times
...
...
Ario
1 year, 3 months ago
Selected Answer: C
D also is correct but considering the principle of least privilege and the given requirements, option C, "Identity Governance Administrator," remains the best choice for User1.
upvoted 1 times
...
Alexbz
1 year, 4 months ago
Selected Answer: D
D : Users with this role can manage role assignments in Azure Active Directory, as well as within Azure AD Privileged Identity Management. They can create and manage groups that can be assigned to Azure AD roles. In addition, this role allows management of all aspects of Privileged Identity Management and administrative units. Under Action you'll find : microsoft.directory/accessReviews/definitions.groupsAssignableToRoles/create >> Create access reviews for membership in groups that are assignable to Azure AD roles https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#privileged-role-administrator
upvoted 3 times
...
billo79152718
1 year, 5 months ago
D is correct. According to Microsoft Documentation. https://learn.microsoft.com/en-us/azure/network-watcher/connection-monitor-connected-machine-agent?tabs=WindowsScript
upvoted 1 times
Malikusmanrasheed
1 year, 4 months ago
That link is off no relevance
upvoted 1 times
...
...
Naszari
1 year, 5 months ago
Selected Answer: D
https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago