nerdexam
Microsoft

AZ-500 · Question #251

You work for an organization using Azure Active Directory (Azure AD) Privileged Identity Management (PIM). You want Abby Brown, a user, to request administrative role elevation before he takes any…

The correct answer is A. Assign Abby Brown the Eligible role membership type. To require a user to request administrative role elevation before taking action in Azure AD PIM, the user must be assigned the Eligible role membership type for the desired role.

Submitted by suresh_in· Mar 6, 2026Secure identity and access

Question

You work for an organization using Azure Active Directory (Azure AD) Privileged Identity Management (PIM). You want Abby Brown, a user, to request administrative role elevation before he takes any administrative action in Azure. What should be your step of action?

Options

  • AAssign Abby Brown the Eligible role membership type.
  • BPerform a resource audit on Abby Brown.
  • CInvite Abby Brown to an access review.
  • DRequire Abby Brown to use Azure multi-factor authentication (MFA).

How the community answered

(30 responses)
  • A
    90% (27)
  • B
    3% (1)
  • C
    7% (2)

Why each option

To require a user to request administrative role elevation before taking action in Azure AD PIM, the user must be assigned the Eligible role membership type for the desired role.

AAssign Abby Brown the Eligible role membership type.Correct

In Azure AD Privileged Identity Management (PIM), assigning a user as "Eligible" for a role means they do not have the permissions by default, but can activate the role when needed. This activation process typically involves requesting elevation, fulfilling any configured requirements like MFA or approval, and then the role is granted for a limited time.

BPerform a resource audit on Abby Brown.

Performing a resource audit assesses access to resources but does not configure the mechanism for a user to request elevated permissions.

CInvite Abby Brown to an access review.

Inviting a user to an access review is for periodically verifying existing role assignments, not for configuring a process for requesting temporary elevation.

DRequire Abby Brown to use Azure multi-factor authentication (MFA).

Requiring MFA enhances the security of a user's login but does not configure a process for role elevation through PIM.

Concept tested: Azure AD PIM eligible role assignment for just-in-time access

Source: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-assign-azure-ad-roles

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice