nerdexam
Microsoft

AZ-500 · Question #448

You have an Azure subscription linked to an Azure AD tenant named contoso.com. Contoso.com contains a user named User1 and an Azure web app named App1. You plan to enable User1 to perform the…

The correct answer is A. Authentication Policy Administrator D. Application Administrator. https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable- credentials-configure-tenant Ensure that you have the global administrator or the authentication policy administrator permission for the directory you want to configure. If you're not…

Submitted by amina.ke· Mar 6, 2026Secure identity and access

Question

You have an Azure subscription linked to an Azure AD tenant named contoso.com. Contoso.com contains a user named User1 and an Azure web app named App1. You plan to enable User1 to perform the following tasks: - Configure contoso.com to use Microsoft Entra Verified ID. - Register App1 in contoso.com. You need to identify which roles to assign to User1. The solution must use the principle of least privilege. Which two roles should you identify? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • AAuthentication Policy Administrator
  • BAuthentication Administrator
  • CCloud App Security Administrator
  • DApplication Administrator
  • EUser Administrator

How the community answered

(25 responses)
  • A
    60% (15)
  • B
    12% (3)
  • C
    24% (6)
  • E
    4% (1)

Explanation

https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable- credentials-configure-tenant Ensure that you have the global administrator or the authentication policy administrator permission for the directory you want to configure. If you're not the global administrator, you need the application administrator permission to complete the app registration including granting admin

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice