nerdexam
Microsoft

SC-300 · Question #300

You have a Microsoft Entra tenant that contains the groups shown in the following table. You need to implement Privileged Identity Management (PIM) for the groups. Which groups can be managed by…

The correct answer is C. Group1 and Group3 only. Groups in Microsoft Entra ID can be classified as either role-assignable or non-role-assignable. Additionally, any group can be enabled or not enabled for use with Microsoft Entra Privileged Identity Management (PIM) for Groups. These are independent properties of the group…

Submitted by thandi_sa· Mar 6, 2026Plan and implement identity governance

Question

You have a Microsoft Entra tenant that contains the groups shown in the following table. You need to implement Privileged Identity Management (PIM) for the groups. Which groups can be managed by using PIM?

Options

  • AGroup1 only
  • BGroup1 and Group2 only
  • CGroup1 and Group3 only
  • DGroup3 and Group4 only
  • EGroup1, Group2, Group3, and Group4

How the community answered

(32 responses)
  • A
    3% (1)
  • C
    84% (27)
  • D
    3% (1)
  • E
    9% (3)

Explanation

Groups in Microsoft Entra ID can be classified as either role-assignable or non-role-assignable. Additionally, any group can be enabled or not enabled for use with Microsoft Entra Privileged Identity Management (PIM) for Groups. These are independent properties of the group. Any Microsoft Entra security group and any Microsoft 365 group (except dynamic groups and groups synchronized from on-premises environment) can be enabled in PIM for Groups. The group doesn't have to be role-assignable group to be enabled in PIM for Groups. https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/concept-

Topics

#Privileged Identity Management#PIM for groups#eligible groups#security groups

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice