AZ-500 · Question #307
Your company recently created an Azure subscription. You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM). Which of the…
The correct answer is A. The Global administrator role. Azure AD PIM Role Assignment Global Administrator (Option A) is correct because it is the only role that grants full permissions to enable and configure Azure AD Privileged Identity Management. When a new Azure subscription is created, only a Global Administrator has the…
Question
Options
- AThe Global administrator role.
- BThe Security administrator role.
- CThe Password administrator role.
- DThe Compliance administrator role.
How the community answered
(16 responses)- A88% (14)
- C6% (1)
- D6% (1)
Explanation
Azure AD PIM Role Assignment
Global Administrator (Option A) is correct because it is the only role that grants full permissions to enable and configure Azure AD Privileged Identity Management. When a new Azure subscription is created, only a Global Administrator has the authority to initially set up PIM, as this requires the highest level of tenant-wide administrative access.
Why the other options are wrong:
- Security Administrator (B) can manage security settings and policies but lacks the elevated permissions required to implement PIM from scratch
- Password Administrator (C) is a limited role focused solely on resetting passwords and has no relevance to PIM configuration
- Compliance Administrator (D) manages compliance-related features and policies but does not have the necessary permissions to deploy or configure PIM
Memory Tip: Think of PIM as the "keys to the kingdom" - only the Global Admin holds the master key. Remember: Global = Greatest access, and you need the greatest access to manage privileged identities. If a question asks about initially setting up or implementing PIM, always default to Global Administrator.
Topics
Community Discussion
No community discussion yet for this question.