AZ-500 · Question #123
Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table. From Azure AD Privileged Identity Management (PIM), you configure the…
The correct answer is User1 can only activate the Security Administrator role in five hours. = No; If User2 activates the Security Administrator role, the user will be assigned the role immediately. = No; User3 can activate the Security Administrator role. = Yes. User1 is a member of Group1, which has an Active assignment type, meaning the Security Administrator role is already permanently active - no activation is required, so the claim that User1 can 'only activate' the role in five hours is incorrect (No). User2 is a member of Group2…
Question
Exhibits
Answer Area
- User1 can only activate the Security Administrator role in five hours.No
- If User2 activates the Security Administrator role, the user will be assigned the role immediately.No
- User3 can activate the Security Administrator role.Yes
Explanation
User1 is a member of Group1, which has an Active assignment type, meaning the Security Administrator role is already permanently active - no activation is required, so the claim that User1 can 'only activate' the role in five hours is incorrect (No). User2 is a member of Group2 (Eligible assignment), and based on the PIM settings shown, the role requires approval before activation, meaning it is NOT assigned immediately upon activation request (No). User3 is a guest user but PIM does not inherently block guest users from activating eligible roles - since User3 is a member of Group2 (Eligible), they can activate the Security Administrator role, making this statement correct (Yes).
Topics
Community Discussion
No community discussion yet for this question.



