nerdexam
Microsoft

SC-300 · Question #224

You have a Microsoft 365 E5 subscription that contains a user named User1. User is eligible for the Application administrator role. User1 needs to configure a new connector group for an application pr

The correct answer is C. the Azure Active Directory admin center. Explanation Activating eligible Privileged Identity Management (PIM) roles in Microsoft 365 E5 requires the Azure Active Directory admin center (now known as the Microsoft Entra admin center), as PIM role activation is a core Azure AD identity governance feature managed directly

Submitted by tom_us· Mar 6, 2026Implement access management for apps

Question

You have a Microsoft 365 E5 subscription that contains a user named User1. User is eligible for the Application administrator role. User1 needs to configure a new connector group for an application proxy. What should you use to activate the role for User1?

Options

  • Athe Microsoft Defender for Cloud Apps portal
  • Bthe Microsoft 365 admin center
  • Cthe Azure Active Directory admin center
  • Dthe Microsoft 365 Defender portal

How the community answered

(48 responses)
  • A
    2% (1)
  • C
    94% (45)
  • D
    4% (2)

Explanation

Explanation

Activating eligible Privileged Identity Management (PIM) roles in Microsoft 365 E5 requires the Azure Active Directory admin center (now known as the Microsoft Entra admin center), as PIM role activation is a core Azure AD identity governance feature managed directly within that portal. Since User1 is eligible (not permanently assigned) for the Application Administrator role, they must activate it through PIM before configuring the application proxy connector group.

Why the distractors are wrong:

  • Option A (Defender for Cloud Apps): This portal is focused on cloud app security, shadow IT discovery, and threat protection - not role activation.
  • Option B (Microsoft 365 admin center): While it handles basic admin tasks and some role assignments, it does not support PIM-based eligible role activation.
  • Option D (Microsoft 365 Defender portal): This is a security operations tool for threat detection and response, with no functionality for activating PIM roles.

Memory Tip

Think "Identity = Azure AD" - any time a question involves identity management, role activation, or PIM, the answer will almost always point to the Azure Active Directory (Entra) admin center, since it is Microsoft's dedicated identity governance hub.

Topics

#Azure AD Roles#Role Management#Application Proxy#Admin Portals

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice