nerdexam
Microsoft

AZ-101 · Question #32

You are configuring Azure Active Directory (AD) Privileged Identity Management. You need to provide a user named Admin1 with read access to a resource group named RG1 for only one month. The user…

The correct answer is B. Assign an eligible role. Azure AD Privileged Identity Management introduces the concept of an eligible admin. Eligible admins should be users that need privileged access now and then, but not all-day, every day. The role is inactive until the user needs access, then they complete an activation process…

Secure identities

Question

You are configuring Azure Active Directory (AD) Privileged Identity Management. You need to provide a user named Admin1 with read access to a resource group named RG1 for only one month. The user role must be assigned immediately. What should you do?

Options

  • AAssign an active role.
  • BAssign an eligible role.
  • CAssign a permanently active role.
  • DCreate a custom role and a conditional access policy.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    71% (22)
  • C
    6% (2)
  • D
    19% (6)

Explanation

Azure AD Privileged Identity Management introduces the concept of an eligible admin. Eligible admins should be users that need privileged access now and then, but not all-day, every day. The role is inactive until the user needs access, then they complete an activation process and become an active admin for a predetermined amount of time. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-

Topics

#PIM#eligible role#time-bound access#role assignment

Community Discussion

No community discussion yet for this question.

Full AZ-101 Practice