AZ-500 exam dumps

AZ-500 practice question 13 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 13

Select 2

Your organization has just onboarded a new Azure subscription to Microsoft Entra (Azure AD) Privileged Identity Management (PIM). The security team mandates that for the subscription-level Owner role, each assignment must be time-bound, require just-in-time activation, and need approval from the security lead before the role can be activated. Which two settings must you configure in Microsoft Entra PIM to meet these requirements?

  1. A
    1. Set the role assignment type to Eligible instead of Permanent.
  2. B
    1. Set the assignment duration to indefinite and disable access reviews.
  3. C
    1. Enable 'Require approval' in the role settings and specify the security lead as the approver.
  4. D
    1. Disable multi-factor authentication requirements in the activation process.
  5. E
    1. Configure the assignment to be Active, ensuring continuous access without prompting.
Show answer and explanation

Correct answers: A, C

Explanation

In Microsoft Entra Privileged Identity Management, configuring a role as Eligible ensures that users only have privileged access when they explicitly activate the role. This activation can further be guarded with approval, MFA, and time-bound settings. Microsoft recommends using short assignment durations, implementing just-in-time (JIT) activation, and requiring an approver for high-risk roles (such as Owner), which aligns with least-privilege and zero-trust principles. For more details, refer to official PIM documentation at https://learn.microsoft.com/azure/active-directory/privileged-identity-management.

  • A. Correct.
    1. Correct. To implement just-in-time access, you must set roles as Eligible, ensuring that the user must activate the role before use.
  • B. Incorrect.
    1. Incorrect. Indefinite assignment goes against the requirement of time-bound access. Disabling access reviews also undermines continuous oversight of privileged roles.
  • C. Correct.
    1. Correct. Requiring approval and specifying an approver (in this case, the security lead) is necessary to meet the approval requirement.
  • D. Incorrect.
    1. Incorrect. Disabling MFA is not recommended for privileged roles. PIM best practice is to enforce MFA for added security.
  • E. Incorrect.
    1. Incorrect. Making the role assignment Active permanently contradicts the just-in-time principle of requiring users to activate and request approval on demand.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam