AZ-500 exam dumps

AZ-500 practice question 2 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 2

Select 2

You are an Azure Security Engineer at Contoso. Your organization requires just-in-time (JIT) access for privileged roles using Azure AD Privileged Identity Management (PIM). You have assigned the Global Administrator role to specific users through PIM, but they are not being prompted for multi-factor authentication when activating their privileges. Which two steps should you take to ensure that MFA is required on activation for Global Administrator? (Each correct answer presents part of the solution. Choose two.)

  1. A

    Enable 'Require multi-factor authentication on activation' for the Global Administrator role in PIM

  2. B

    Create a custom Conditional Access policy for the Global Administrator role that restricts sign-ins to trusted locations only

  3. C

    Turn on 'User consent for apps' in the Azure AD User settings

  4. D

    Configure the Global Administrator role membership as 'Eligible' instead of 'Active' within PIM

Show answer and explanation

Correct answers: A, D

Explanation

To ensure that Global Administrator privileges follow just-in-time and multi-factor authentication requirements, you must configure the role as 'Eligible' and enable the 'Require multi-factor authentication on activation' setting in Azure AD Privileged Identity Management. This approach aligns with the principle of least privilege, minimizes standing administrative access, and aligns with Microsoft best practices. For more details, refer to the official Microsoft documentation on configuring Azure AD Privileged Identity Management.

  • A. Correct.

    Correct: Enabling 'Require multi-factor authentication on activation' in PIM ensures that users assigned to the role must complete MFA before activating the privileges.

  • B. Incorrect.

    Incorrect: Restricting sign-ins to trusted locations does not enforce MFA on activation. Conditional Access can be useful, but it does not directly enable the just-in-time MFA requirement in PIM without also requiring MFA explicitly.

  • C. Incorrect.

    Incorrect: User consent for apps is unrelated to requiring MFA during role activation. This setting governs how users grant permissions to third-party apps, not privileged role activation.

  • D. Correct.

    Correct: Configuring the role as 'Eligible' requires the user to go through the activation process, during which MFA can be enforced. If the role is set to 'Active,' the user is granted standing privileges and will bypass the just-in-time activation steps.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam