SC-300 · Question #224
You have a Microsoft 365 E5 subscription that contains a user named User1. User is eligible for the Application administrator role. User1 needs to configure a new connector group for an application pr
The correct answer is C. the Azure Active Directory admin center. Explanation Activating eligible Privileged Identity Management (PIM) roles in Microsoft 365 E5 requires the Azure Active Directory admin center (now known as the Microsoft Entra admin center), as PIM role activation is a core Azure AD identity governance feature managed directly
Question
You have a Microsoft 365 E5 subscription that contains a user named User1. User is eligible for the Application administrator role. User1 needs to configure a new connector group for an application proxy. What should you use to activate the role for User1?
Options
- Athe Microsoft Defender for Cloud Apps portal
- Bthe Microsoft 365 admin center
- Cthe Azure Active Directory admin center
- Dthe Microsoft 365 Defender portal
How the community answered
(48 responses)- A2% (1)
- C94% (45)
- D4% (2)
Explanation
Explanation
Activating eligible Privileged Identity Management (PIM) roles in Microsoft 365 E5 requires the Azure Active Directory admin center (now known as the Microsoft Entra admin center), as PIM role activation is a core Azure AD identity governance feature managed directly within that portal. Since User1 is eligible (not permanently assigned) for the Application Administrator role, they must activate it through PIM before configuring the application proxy connector group.
Why the distractors are wrong:
- Option A (Defender for Cloud Apps): This portal is focused on cloud app security, shadow IT discovery, and threat protection - not role activation.
- Option B (Microsoft 365 admin center): While it handles basic admin tasks and some role assignments, it does not support PIM-based eligible role activation.
- Option D (Microsoft 365 Defender portal): This is a security operations tool for threat detection and response, with no functionality for activating PIM roles.
Memory Tip
Think "Identity = Azure AD" - any time a question involves identity management, role activation, or PIM, the answer will almost always point to the Azure Active Directory (Entra) admin center, since it is Microsoft's dedicated identity governance hub.
Topics
Community Discussion
No community discussion yet for this question.