nerdexam
Microsoft

SC-300 · Question #285

You have a Microsoft 365 E5 subscription that contains a user named User1. User1 is eligible for the Application Administrator role. User1 needs to configure a new connector group for an application…

The correct answer is D. the Azure Active Directory admin center. Explanation Option D is correct because Privileged Identity Management (PIM) role activation - including activating the Application Administrator role - is managed through the Azure Active Directory (Entra ID) admin center, which is the dedicated identity and access management…

Submitted by joshua94· Mar 6, 2026Implement access management for apps

Question

You have a Microsoft 365 E5 subscription that contains a user named User1. User1 is eligible for the Application Administrator role. User1 needs to configure a new connector group for an application proxy. What should you use to activate the role for User1?

Options

  • Athe Microsoft 365 Defender portal
  • Bthe Microsoft 365 admin center
  • Cthe Microsoft Intune admin center
  • Dthe Azure Active Directory admin center

How the community answered

(27 responses)
  • B
    4% (1)
  • C
    4% (1)
  • D
    93% (25)

Explanation

Explanation

Option D is correct because Privileged Identity Management (PIM) role activation - including activating the Application Administrator role - is managed through the Azure Active Directory (Entra ID) admin center, which is the dedicated identity and access management portal for Microsoft 365. PIM allows eligible users like User1 to activate their assigned roles on-demand, which is required before performing tasks like configuring Application Proxy connector groups.

Why the distractors are wrong:

  • Option A (Microsoft 365 Defender) is focused on security operations, threat protection, and compliance - not role activation or identity management.
  • Option B (Microsoft 365 admin center) handles general Microsoft 365 administration (users, licenses, services) but does not provide PIM role activation capabilities.
  • Option C (Microsoft Intune admin center) is specifically for device and application management (MDM/MAM) and has no functionality for activating Azure AD roles.

Memory Tip

Think "Identity tasks = Azure AD/Entra ID" - any time a question involves role activation, PIM, Conditional Access, or Application Proxy, your answer will almost always point to the Azure Active Directory (Entra ID) admin center, since it is the central hub for all identity and access management in Microsoft 365.

Topics

#Azure AD Roles#Role Activation#Application Administrator#Azure AD Admin Center

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice