AZ-500 · Question #180
Case Study 1 - Litware, Inc Overview Litware, Inc. is a digital media company that has 500 employees in the Chicago area and 20 employees in the San Francisco area. Existing Environment Litware has…
This hotspot question tests knowledge of Azure AD identity and access management configurations, specifically around PIM role assignments, dynamic group membership rules, and Azure AD application registration restrictions.
Question
Exhibit
Answer Area
- To configure the registration settings:Azure AD – User settingsAzure AD – App registrations settingsEnterprise Applications – User settings
- To configure the consent settings:Azure AD – User settingsAzure AD – App registrations settingsEnterprise Applications – User settings
Explanation
This hotspot question tests knowledge of Azure AD identity and access management configurations, specifically around PIM role assignments, dynamic group membership rules, and Azure AD application registration restrictions.
Approach. For San Francisco users and devices to automatically become members of Group1, the group must use a dynamic membership rule based on location attributes (e.g., city = 'San Francisco'). For Group2 members to have a permanent eligible Contributor assignment to Resource Group2, this is configured in Azure AD PIM under Azure Resource roles, selecting 'Eligible' assignment type with no end date (permanent). To prevent users from registering applications, the Azure AD tenant setting 'Users can register applications' must be set to 'No' under Azure Active Directory > User settings. Each of these configurations maps to specific Yes/No or selection answers in the hotspot grid based on whether the described configuration achieves the stated requirement.
Concept tested. Azure AD Privileged Identity Management (PIM) permanent eligible role assignments, Azure AD dynamic group membership rules for user/device objects, and Azure AD tenant-level user settings for application registration restrictions.
Reference. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-resource-roles-assign-roles | https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-dynamic-membership | https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-how-applications-are-added#who-has-permission-to-add-applications-to-my-azure-ad-instance
Topics
Community Discussion
No community discussion yet for this question.
