nerdexam
Microsoft

AZ-500 · Question #307

Your company recently created an Azure subscription. You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM). Which of the…

The correct answer is A. The Global administrator role. Azure AD PIM Role Assignment Global Administrator (Option A) is correct because it is the only role that grants full permissions to enable and configure Azure AD Privileged Identity Management. When a new Azure subscription is created, only a Global Administrator has the…

Submitted by kim_seoul· Mar 6, 2026Secure identity and access

Question

Your company recently created an Azure subscription. You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM). Which of the following is the role you should assign to the user?

Options

  • AThe Global administrator role.
  • BThe Security administrator role.
  • CThe Password administrator role.
  • DThe Compliance administrator role.

How the community answered

(16 responses)
  • A
    88% (14)
  • C
    6% (1)
  • D
    6% (1)

Explanation

Azure AD PIM Role Assignment

Global Administrator (Option A) is correct because it is the only role that grants full permissions to enable and configure Azure AD Privileged Identity Management. When a new Azure subscription is created, only a Global Administrator has the authority to initially set up PIM, as this requires the highest level of tenant-wide administrative access.

Why the other options are wrong:

  • Security Administrator (B) can manage security settings and policies but lacks the elevated permissions required to implement PIM from scratch
  • Password Administrator (C) is a limited role focused solely on resetting passwords and has no relevance to PIM configuration
  • Compliance Administrator (D) manages compliance-related features and policies but does not have the necessary permissions to deploy or configure PIM

Memory Tip: Think of PIM as the "keys to the kingdom" - only the Global Admin holds the master key. Remember: Global = Greatest access, and you need the greatest access to manage privileged identities. If a question asks about initially setting up or implementing PIM, always default to Global Administrator.

Topics

#Azure AD PIM#Azure AD roles#Role-based access control

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice