exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 64 discussion

Actual exam question from Microsoft's AZ-500
Question #: 64
Topic #: 2
[All AZ-500 Questions]

You have an Azure subscription that uses Azure Active Directory (Azure AD) Privileged Identity Management (PIM).
A PIM user that is assigned the User Access Administrator role reports receiving an authorization error when performing a role assignment or viewing the list of assignments.
You need to resolve the issue by ensuring that the PIM service principal has the correct permissions for the subscription. The solution must use the principle of least privilege.
Which role should you assign to the PIM service principle?

  • A. Contributor
  • B. User Access Administrator
  • C. Managed Application Operator
  • D. Resource Policy Contributor
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Vikku30
Highly Voted 2 years, 11 months ago
The english of question is too confusing to understand. Who writes these questions
upvoted 51 times
...
Fal991l
Highly Voted 2 years, 1 month ago
whoever figured out the proper answer must be a genius.
upvoted 10 times
femzy
1 year ago
I didn't even answer it. My first approach was to come to the comments to see other people's logic towards answering this question.
upvoted 2 times
...
...
JBAnalyst
Most Recent 1 week ago
Selected Answer: B
The PIM service principal needs to have that role assigned to the user in order for it to function . The PIM service itself needs the role too
upvoted 1 times
...
8de3321
2 weeks, 3 days ago
Selected Answer: D
This exact same question is in #113 Topic 2 (paid part of this website) and even this website has shown the answer mixed up compared to #63. This is so messed up. Guys if you are purchasing this questions from this website, do not blindly trust the answers. Know that only a few has purchased it and so the votes and discussion is significantly low. The answers are also messed up but you will get many more questions. If you are too good at finding answers yourself or want to prepare so badly then go for it otherwise it is absolutely a waste of money in my opinion.
upvoted 1 times
...
ITFranz
4 months, 1 week ago
The question states, A PIM user that is assigned the User Access Administrator ( it already has it assigned ). To support the answer. https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-troubleshoot#access-to-azure-resources-denied Access to Azure resources denied Problem As an active owner or user access administrator for an Azure resource, you are able to see your resource inside Privileged Identity Management but can't perform any actions such as making an eligible assignment or viewing a list of role assignments from the resource overview page. Any of these actions results in an authorization error. Cause This problem can happen when the User Access Administrator role for the PIM service principal was accidentally removed from the subscription. For the Privileged Identity Management service to be able to access Azure resources, the MS-PIM service principal should always have the User Access Administrator role role assigned.
upvoted 1 times
...
ESAJRR
1 year, 2 months ago
Selected Answer: B
B. User Access Administrator
upvoted 2 times
...
ErikPJordan
1 year, 2 months ago
Weird question.
upvoted 3 times
...
TheProfessor
1 year, 2 months ago
Selected Answer: B
This question was tricky. But answer B is correct answer.
upvoted 2 times
...
zellck
1 year, 7 months ago
Selected Answer: B
B is the answer. https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-troubleshoot#access-to-azure-resources-denied Assign the User Access Administrator role to the Privileged identity Management service principal name (MS–PIM) at the subscription level. This assignment should allow the Privileged identity Management service to access the Azure resources.
upvoted 7 times
...
Bentos2004
1 year, 7 months ago
Wow, very tricky
upvoted 1 times
...
Snaileyes
1 year, 7 months ago
Here's a current reference link: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-troubleshoot#access-to-azure-resources-denied
upvoted 2 times
...
majstor86
1 year, 9 months ago
B. User Access Administrator
upvoted 2 times
...
somenick
2 years, 2 months ago
The question is related to this article: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-troubleshoot However I can not find MS-PIM service principal
upvoted 3 times
...
BP_lobster
2 years, 8 months ago
Selected Answer: B
Note the question is asking what role we should assign the SERVICE principle. The role mentioned in the question is assigned to a USER. The question is confusingly worded, but the above distinction helped me answer it.
upvoted 6 times
...
DanHeg
2 years, 9 months ago
Very confusing to work out what it's asking for, as the answer is in the question but the question suggests it's not enough
upvoted 3 times
...
Patchfox
2 years, 11 months ago
Selected Answer: B
It's B
upvoted 1 times
...
HananS
2 years, 12 months ago
https://docs.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin The answer seems correct
upvoted 1 times
cfsxtuv33
2 years, 11 months ago
According to the link you provided I agree, the answer is correct.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago