AZ-500 exam dumps

AZ-500 practice question 15 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 15

Single answer

You are a security administrator for an organization that manages multiple Azure subscriptions. You want to provide a group of security engineers with the Owner role for a specific subscription via Microsoft Entra Privileged Identity Management (PIM). Their access should be subject to just-in-time activation, require approval each time they elevate their privileges, and ensure no one has continuous Owner access by default. Which approach should you implement?

  1. A

    Use PIM to assign active roles to the security engineers and specify an indefinite assignment duration for the subscription.

  2. B

    Onboard the subscription to PIM, assign the security engineers as eligible Owners, and configure approval settings for role activation.

  3. C

    Set up the security engineers as permanent Owners without requiring an activation process for any elevated actions on the subscription.

  4. D

    Use PIM to grant Security Reader roles to the engineers and enable multi-factor authentication (MFA) without assigning Owner privileges.

Show answer and explanation

Correct answer: B

Explanation

In Microsoft Entra Privileged Identity Management, marking users or groups as 'eligible' for a specific role (such as Owner) enforces a just-in-time model, requiring them to activate the role before using its privileges. By configuring an approval process, each activation request must be approved, preventing unauthorized or continuous ownership. This follows best practices for least privilege and ensures compliance by granting high-level permissions only when needed. Refer to the Microsoft documentation on Microsoft Entra PIM for more details on setting eligible assignments and approval workflows.

  • A. Incorrect.

    Option 1 is incorrect because assigning active roles with an indefinite duration contradicts the just-in-time principle, as it grants continuous high-level access without requiring activation.

  • B. Correct.

    Option 2 is correct. By marking the group as eligible Owners, you ensure they do not possess continuous privileges, and configuring approval settings enforces an approval workflow each time they elevate to Owner.

  • C. Incorrect.

    Option 3 is incorrect because making the security engineers permanent Owners means they would have constant high-level permissions; this does not meet the requirement to prevent continuous Owner access.

  • D. Incorrect.

    Option 4 is incorrect because assigning Security Reader roles lacks the elevated privileges required to manage the subscription fully. It also does not address the requirement for Owner-level just-in-time access.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam