nerdexam
Microsoft

AZ-500 · Question #93

Hotspot Question You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table. Azure AD Privileged Identity Management (PIM) is enabled…

The correct answer is When User1 signs in, the user is assigned the Password Administrator role automatically. = Yes; User2 can request to activate the Password Administrator role. = Yes; If User3 wants to activate the Password Administrator role, the user can approve their own request. = No. Here's the breakdown: 1. When User1 signs in, the user is assigned the Password Administrator role automatically. => Yes The table shows User1 has an "Active" assignment type for the Password Administrator role. According to the explanation, an "Active" assignment means the…

Submitted by tyler.j· Mar 6, 2026Secure identity and access

Question

Hotspot Question You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table. Azure AD Privileged Identity Management (PIM) is enabled for the tenant. In PIM, the Password Administrator role has the following settings: - Maximum activation duration (hours): 2 - Send email notifying admins of activation: Disable - Require incident/request ticket number during activation: Disable - Require Azure Multi-Factor Authentication for activation: Enable - Require approval to activate this role: Enable - Selected approver: Group1 You assign users the Password Administrator role as shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-500 question #93 exhibit 1
AZ-500 question #93 exhibit 2
AZ-500 question #93 exhibit 3
AZ-500 question #93 exhibit 4
AZ-500 question #93 exhibit 5
AZ-500 question #93 exhibit 6

Answer Area

  • When User1 signs in, the user is assigned the Password Administrator role automatically.Yes
  • User2 can request to activate the Password Administrator role.Yes
  • If User3 wants to activate the Password Administrator role, the user can approve their own request.No

Explanation

Here's the breakdown:

  1. When User1 signs in, the user is assigned the Password Administrator role automatically. => Yes

    • The table shows User1 has an "Active" assignment type for the Password Administrator role. According to the explanation, an "Active" assignment means the user does not need to go through the activation process. The role is directly assigned upon signing in, making the activation requirements (like MFA) irrelevant for this user. Thus, User1 receives the role automatically.
  2. User2 can request to activate the Password Administrator role. => Yes

    • The table indicates User2 has an "Eligible" assignment type for the Password Administrator role. An "Eligible" assignment means the user can request to activate the role. The question asks if User2 can request, not if they can successfully complete the activation process (which would require meeting PIM's MFA and approval requirements). The explanation confirms that an eligible user can indeed make a request for activation.
  3. If User3 wants to activate the Password Administrator role, the user can approve their own request. => No

    • User3 has an "Eligible" assignment and is a member of "Group1". The PIM settings for the Password Administrator role state that approval is required to activate the role, and "Group1" is the selected approver. However, PIM policies prevent a user from approving their own request, even if they are part of the designated approver group. The explanation explicitly states that the requester cannot approve their own request, and others in the group would receive it for approval.

Topics

#Privileged Identity Management (PIM)#Azure AD roles#Just-In-Time activation#Role approval workflows

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice