nerdexam
Microsoft

AZ-500 · Question #152

You have an Azure subscription. You configure the subscription to use a different Azure Active Directory (Azure AD) tenant. What are two possible effects of the change? Each correct answer presents…

The correct answer is A. Role assignments at the subscription level are lost. B. Virtual machine managed identities are lost. Transferring an Azure Subscription to a Different Azure AD Tenant When you move an Azure subscription to a different Azure AD tenant, role assignments (RBAC) are permanently deleted because those assignments are tied to user/group/service principal object IDs that exist in the…

Submitted by stefanr· Mar 6, 2026Secure identity and access

Question

You have an Azure subscription. You configure the subscription to use a different Azure Active Directory (Azure AD) tenant. What are two possible effects of the change? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • ARole assignments at the subscription level are lost.
  • BVirtual machine managed identities are lost.
  • CVirtual machine disk snapshots are lost.
  • DExisting Azure resources are deleted.

How the community answered

(39 responses)
  • A
    85% (33)
  • C
    5% (2)
  • D
    10% (4)

Explanation

Transferring an Azure Subscription to a Different Azure AD Tenant

When you move an Azure subscription to a different Azure AD tenant, role assignments (RBAC) are permanently deleted because those assignments are tied to user/group/service principal object IDs that exist in the original tenant - they have no meaning in the new tenant and cannot be migrated. Similarly, managed identities for virtual machines are lost because managed identities are Azure AD objects (either system-assigned or user-assigned) that exist within a specific tenant; when the subscription moves, those identity objects no longer exist in the new tenant's context and must be recreated.

Why C and D are wrong: Disk snapshots (C) are Azure resource objects stored independently of Azure AD - they remain intact after a tenant transfer. Existing Azure resources (D) are not deleted during a tenant transfer; the resources themselves (VMs, storage accounts, databases, etc.) continue to exist, which is a key point of the operation.

Memory Tip: Think of Azure AD as a security/identity layer sitting on top of your resources. Moving tenants wipes anything tied to identity (role assignments, managed identities) but leaves the underlying infrastructure resources untouched - "Identity goes, infrastructure stays."

Topics

#Azure Active Directory#Subscription Management#Role-Based Access Control (RBAC)#Managed Identities

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice