nerdexam
Microsoft

AZ-500 · Question #220

Your network contains an on-premises Active Directory domain named adatum.com that syncs to Azure Active Directory (Azure AD). Azure AD Connect is installed on a domain member server named Server1…

The correct answer is B. Global administrator. Explanation Global Administrator (B) is correct because modifying Azure AD Connect synchronization options requires Global Administrator privileges in Azure AD - this is a specific Microsoft requirement, as the Azure AD Connect configuration wizard explicitly needs this role to…

Submitted by kev92· Mar 6, 2026Secure identity and access

Question

Your network contains an on-premises Active Directory domain named adatum.com that syncs to Azure Active Directory (Azure AD). Azure AD Connect is installed on a domain member server named Server1. You need to ensure that a domain administrator for the adatum.com domain can modify the synchronization options. The solution must use the principle of least privilege. Which Azure AD role should you assign to the domain administrator?

Options

  • ASecurity administrator
  • BGlobal administrator
  • CUser administrator

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    88% (28)
  • C
    6% (2)

Explanation

Explanation

Global Administrator (B) is correct because modifying Azure AD Connect synchronization options requires Global Administrator privileges in Azure AD - this is a specific Microsoft requirement, as the Azure AD Connect configuration wizard explicitly needs this role to make changes to synchronization settings, and there is no lower-privileged role that grants this capability.

Security Administrator (A) is incorrect because this role is focused on managing security policies, alerts, and identity protection settings - it does not grant the ability to configure or modify Azure AD Connect synchronization options.

User Administrator (C) is incorrect because this role is scoped to managing user accounts, groups, and password resets, and has no permissions related to directory synchronization configuration.

Memory Tip: Think of Azure AD Connect as the "master bridge" between on-premises AD and Azure AD - only the highest-ranking Azure AD role (Global Administrator) holds the keys to modify how that bridge works. While this seems to violate least privilege in spirit, it's a Microsoft-imposed technical requirement, not a design choice - so on the exam, remember: "sync changes = Global Admin."

Topics

#Azure AD Connect#Azure AD Roles#Hybrid Identity#Least Privilege

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice