nerdexam
Microsoft

AZ-500 · Question #379

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains two administrative units named AU1 and AU2. Users are assigned to the administrative units as shown in the…

The correct answer is Admin1 can reset the password of User1. = Yes; Admin2 can reset the password of User3. = No; Admin3 can reset the password of Admin4. = No. Admin1 holds a User Administrator role scoped to AU1, and User1 is a member of AU1, so Admin1 can reset User1's password within that administrative unit scope. Admin2 cannot reset User3's password because User3 is not a member of the administrative unit to which Admin2's role…

Submitted by neha2k· Mar 6, 2026Manage Azure Active Directory identities and governance - specifically, configuring and managing administrative units and understanding the scope and limitations of delegated administrative roles in Azure AD (Microsoft Entra ID).

Question

Hotspot Question You have an Azure Active Directory (Azure AD) tenant that contains two administrative units named AU1 and AU2. Users are assigned to the administrative units as shown in the following table. Users are assigned the roles shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-500 question #379 exhibit 1
AZ-500 question #379 exhibit 2
AZ-500 question #379 exhibit 3
AZ-500 question #379 exhibit 4
AZ-500 question #379 exhibit 5
AZ-500 question #379 exhibit 6

Answer Area

  • Admin1 can reset the password of User1.Yes
  • Admin2 can reset the password of User3.No
  • Admin3 can reset the password of Admin4.No

Explanation

Admin1 holds a User Administrator role scoped to AU1, and User1 is a member of AU1, so Admin1 can reset User1's password within that administrative unit scope. Admin2 cannot reset User3's password because User3 is not a member of the administrative unit to which Admin2's role is scoped - administrative unit-scoped roles only apply to users within that specific AU. Admin3 cannot reset Admin4's password because Admin4 is an administrator, and Password Administrators (or similarly scoped roles) cannot reset passwords for other administrators - only Global Administrators can reset passwords for other privileged users, and even then, scoping restrictions and role hierarchy rules apply.

Topics

#Azure AD Administrative Units#Role-Based Access Control (RBAC)#Password Reset Permissions#Delegated Administration

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice