D.
https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps
"You can assign a role to a user, group, service principal, or managed identity. "
App1 has service principal.
https://learn.microsoft.com/en-us/azure/active-directory/develop/howto-create-service-principal-portal
The Contributor role can be assigned to any Azure resource, including users, groups, service principals, and managed identities.
• Group1 is a dynamic device security group in Azure AD. Dynamic groups are not role-assignable, so Group1 cannot be assigned the Contributor role for VM1.
• Managed1 is a managed identity. Managed identities can be assigned the Contributor role for VM1.
• VM1 is a virtual machine. Virtual machines can be assigned the Contributor role for themselves.
• App1 is an enterprise application in Azure AD. Enterprise applications can be assigned the Contributor role for VM1.
Therefore, the only resources that can be assigned the Contributor role for VM1 are Managed1, VM1, and App1.
You can’t assign RBAC to a “dynamic” group type which is what group 1 is
All answers that have group 1 is automatically wrong
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/groups-concept
I wish this website gave answers instead of making people fight over the options and confuse people trying to write the exam. I paid for this service and this is what I am presented with. What is this exam, if people cannot find the proper answer on the Microsoft website even with access and then expects people to do it under time pressure with very minimal access? This is insane. If this was the exam I would choose option D or something because I don't think Microsoft would make the question too easy to find with the method of elimination.
This question is weird, because it should have a choice for: Managed ID, App1 and VM.
Dynamic Entra Sec Groups cannot have roles assigned, all the other can have.
The closet answer to truth is A.
Difference between Azure AD roles and Azure RBAC is as follows:
RBAC can have a User, group, or service principal, Managed identity (group nesting is allowed and the group can dynamic as well
Azure AD roles only users and groups (group nesting is not allowed as soon as you enable entra roles can be enabled the membership type greys out to assign and group nesting is not allowed.
Here contributor is a RBAC role not azure ad role
D.
https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps
"You can assign a role to a user, group, service principal, or managed identity. "
Tested. When creating a group, if you choose dynamic user "Microsoft Entra roles can be assigned to the group" option turns to NO automatically. So when you eliminate group1, answer is A.
Correct answer is A
role-assignable groups is limited to AD Azure roles
https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept#restrictions-for-role-assignable-groups
https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept
Only Global Administrators and Privileged Role Administrators can create a role-assignable group. The membership type for role-assignable groups must be Assigned and can't be an Azure AD dynamic group.Automated population of dynamic groups could lead to an unwanted account being added to the group and thus assigned to the role.
Answer is A;
You can assign a role to a user, group, service principal, or managed identity. This is also called a security principal.
https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-steps#step-1-determine-who-needs-access
Cannot be a dynamic group;
https://learn.microsoft.com/en-us/azure/active-directory/roles/groups-concept#how-are-role-assignable-groups-protected
This section is not available anymore. Please use the main Exam Page.AZ-500 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
973b658
Highly Voted 1 year, 11 months agobasak
1 year, 8 months agoliorh
1 year, 10 months agoFranc_Coetzee
1 year, 10 months agopentium75
9 months agobxlin
11 months, 2 weeks agoOrangeSG
Highly Voted 1 year, 6 months agoJBAnalyst
Most Recent 4 months, 3 weeks ago8de3321
5 months agofenth7
5 months agopentium75
9 months agoACSC
1 year, 1 month agocris_exam
1 year, 3 months ago[Removed]
1 year, 4 months agoWilianCArias
1 year, 4 months agoManiMessner
1 year, 5 months agorosef
1 year, 5 months agoxRiot007
9 months, 2 weeks agowardy1983
1 year, 5 months agoErikPJordan
1 year, 7 months agoInnoMaf
1 year, 7 months agopentium75
9 months agovcloudpmp
1 year, 8 months agoITTesters
1 year, 9 months ago