nerdexam
MicrosoftMicrosoft

AZ-500 · Question #7

AZ-500 Question #7: Real Exam Question with Answer & Explanation

The correct answer is A: Assign User2 the Global administrator role.. Explanation To enable Azure AD Privileged Identity Management (PIM) for a tenant, the user performing the initial setup must hold the Global Administrator role, as PIM requires tenant-level administrative consent to be activated - this is a prerequisite that cannot be bypassed. O

Submitted by brentm· Mar 6, 2026Secure identity and access

Question

Case Study 2 - Contoso, Ltd Overview Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York. The company hosts its entire server infrastructure in Azure. Contoso has two Azure subscriptions named Sub1 and Sub2. Both subscriptions are associated to an Azure Active Directory (Azure AD) tenant named contoso.com. Technical requirements Contoso identifies the following technical requirements: Deploy Azure Firewall to VNetWork1 in Sub2. Register an application named App2 in contoso.com. Whenever possible, use the principle of least privilege. Enable Azure AD Privileged Identity Management (PIM) for contoso.com Existing Environment Azure AD Contoso.com contains the users shown in the following table. Contoso.com contains the security groups shown in the following table. Sub1 Sub1 contains six resource groups named RG1, RG2, RG3, RG4, RG5, and RG6. User2 creates the virtual networks shown in the following table. Sub1 contains the locks shown in the following table. Sub1 contains the Azure policies shown in the following table. Sub2 Sub2 contains the virtual machines shown in the following table. All virtual machines have the public IP addresses and the Web Server (IIS) role installed. The firewalls for each virtual machine allow ping requests and web requests. Sub2 contains the network security groups (NSGs) shown in the following table. NSG1 has the inbound security rules shown in the following table. NSG2 has the inbound security rules shown in the following table. NSG3 has the inbound security rules shown in the following table. NSG4 has the inbound security rules shown in the following table. NSG1, NSG2, NSG3, and NSG4 have the outbound security rules shown in the following table. Contoso identifies the following technical requirements: Deploy Azure Firewall to VNetwork1 in Sub2. Register an application named App2 in contoso.com. Whenever possible, use the principle of least privilege. Enable Azure AD Privileged Identity Management (PIM) for contoso.com. You need to ensure that User2 can implement PIM. What should you do first?

Options

  • AAssign User2 the Global administrator role.
  • BConfigure authentication methods for contoso.com.
  • CConfigure the identity secure score for contoso.com.
  • DEnable multi-factor authentication (MFA) for User2.

Explanation

Explanation

To enable Azure AD Privileged Identity Management (PIM) for a tenant, the user performing the initial setup must hold the Global Administrator role, as PIM requires tenant-level administrative consent to be activated - this is a prerequisite that cannot be bypassed. Option B (configuring authentication methods) is irrelevant to enabling PIM, as authentication methods relate to sign-in security configurations, not PIM activation. Option C (identity secure score) is a monitoring/recommendation feature that has no bearing on enabling PIM. Option D (enabling MFA for User2) is a common distractor because MFA is eventually recommended for PIM users, but MFA alone does not grant the permissions needed to enable PIM in the first place.

Memory Tip: Think of PIM as a "master key" system for the tenant - only the person with the master key (Global Administrator) can install the system. You can't set up the lockbox without first being the locksmith. When a question asks what to do first before implementing PIM, always look for Global Administrator assignment.

Topics

#Azure AD PIM#Role assignment#Global Administrator#Identity governance

Community Discussion

No community discussion yet for this question.

Full AZ-500 PracticeBrowse All AZ-500 Questions