exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 4 question 80 discussion

Actual exam question from Microsoft's AZ-500
Question #: 80
Topic #: 4
[All AZ-500 Questions]

You have an Azure Active Directory (Azure AD) tenant that contains a user named User1.
You plan to enable passwordless authentication for the tenant.
You need to ensure that User1 can enable the combined registration experience. The solution must use the principle of least privilege.
Which role should you assign to User1?

  • A. Security administrator
  • B. Privileged role administrator
  • C. Authentication administrator
  • D. Global administrator
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
somenick
Highly Voted 2 years, 2 months ago
Selected Answer: D
Answer and reference is wrong. The correct one: User admin or Global admin. See here: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-registration-mfa-sspr-combined
upvoted 6 times
xRiot007
3 months, 1 week ago
Page is not very clear. It just says "Sign in to the Microsoft Entra admin center as at least an Conditional Access Administrator"
upvoted 1 times
...
...
epomatti
Highly Voted 11 months, 2 weeks ago
Selected Answer: D
Ok, I've figured this one out. The OLD method does require Global Administrator. So, the provided answer is correct. However, the NEW way of doing this require at least Authentication Policy Administrators. "The Authentication methods policy is the recommended way to manage authentication methods, including modern methods like passwordless authentication. Authentication Policy Administrators can edit this policy to enable authentication methods for all users or specific groups." Both scenarios are explained here: https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-methods-manage
upvoted 6 times
...
8de3321
Most Recent 4 days, 22 hours ago
Selected Answer: D
A very similar question is in the practice assessment and the answer is Global Admin, which is the role that is needed to do this.
upvoted 1 times
...
Viggy1212
2 months, 2 weeks ago
Selected Answer: D
To enable passwordless authentication for the tenant, User1 needs to have Authentication Administrator role. But to enable "combined registration experience", User1 needs to have User Administrator Role. Hence Global Admin combines both access. Hence D.
upvoted 1 times
...
Jimmy500
5 months, 2 weeks ago
D-Authentication administration can not set it for admin users and question asks about tenant wide configuration that is why we need to go with GA.
upvoted 1 times
...
wardy1983
1 year ago
Answer: D Explanation: Sign in to the Azure portal as a user administrator or global administrator.
upvoted 1 times
...
TheProfessor
1 year, 2 months ago
Selected Answer: D
It is clearly mentioned in this link either User/Global administrator for "combined registration experience." I am wondering, isn't here anyone from ExamTopics to see and update the result? Link: https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-deployment#required-roles
upvoted 3 times
...
Ario
1 year, 5 months ago
Selected Answer: C
this can be done with all of mentioned roles but option c is enough without requiring excessive privileges or access to other administrative functions.
upvoted 1 times
Ario
1 year, 5 months ago
sorry i missed the point of enabling this option not managing which only can be done by Global Admin so correct answer is D
upvoted 1 times
...
...
Amnesia
1 year, 5 months ago
I think the answers y D- Global Administrator https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-deployment#required-roles Required roles Here are the least privileged roles required for this deployment: Azure AD Role Description User Administrator or Global Administrator To implement combined registration experience. Authentication Administrator To implement and manage authentication methods. User To configure Authenticator app on device, or to enroll security key device for web or Windows 10 sign-in.
upvoted 1 times
...
tsaad
1 year, 6 months ago
B is the least priv and can do passwordless. the two admins who can do passwordless are the global admin and the privilege role admin. the least privilege is the privilege role admin so I would choose B.
upvoted 1 times
...
Amnesia
1 year, 6 months ago
C is the correct answer. the question says: The solution must use the principle of least privilege. The Authentication Administrator has the privileges to implement and manage authentication methods. https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-deployment#required-roles
upvoted 1 times
...
zellck
1 year, 7 months ago
Selected Answer: D
D is the answer. https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-deployment#required-roles Here are the least privileged roles required for this deployment: - User Administrator or Global Administrator To implement combined registration experience.
upvoted 4 times
...
majstor86
1 year, 9 months ago
Selected Answer: D
D. Global administrator
upvoted 2 times
...
tutonata
1 year, 9 months ago
Global Admin is required as per docs: https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-deployment#required-roles Authentication Administrator can only implement and manage authentication methods, NOT implement combined registration experiences.
upvoted 2 times
...
CeliaZhou
1 year, 11 months ago
Tried with lab, when granted "Authentication admin", user cannot access Azure Active Directory > User settings > Manage user feature settings, hence not able to enable the combined registration experience. Based on MS documentation: https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-registration-mfa-sspr-combined#enable-combined-registration Need user administrator or global administrator to do that, so I would choose D
upvoted 4 times
...
Ajdlfasudfo0
1 year, 11 months ago
Selected Answer: D
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-registration-mfa-sspr-combined as somenick stated
upvoted 2 times
...
ltjones12
1 year, 11 months ago
Agree with JohnBentass - the authentication administrator can set auth methods for non-admin users. Global Admin is overkill, does not adhere to principle of least privilege
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago