nerdexam
Microsoft

SC-300 · Question #401

You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains the groups shown in the following table. Which groups can you manage by using Privileged Identity…

The correct answer is D. Group1, Group2, and Group3 only. Group1 is security enabled, role assignment is not allowed. Group1 can be managed. All security enabled groups can be manged by PIM. Note: Groups in Microsoft Entra ID can be classified as either role-assignable or non-role- assignable. Additionally, any group can be enabled or…

Submitted by obi.ng· Mar 6, 2026Plan and implement identity governance

Question

You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains the groups shown in the following table. Which groups can you manage by using Privileged Identity Management (PIM)?

Exhibit

SC-300 question #401 exhibit

Options

  • AGroup2 only
  • BGroup1 and Group2 only
  • CGroup2 and Group4 only
  • DGroup1, Group2, and Group3 only
  • EGroup1, Group2, Group3, and Group4

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    6% (3)
  • C
    14% (7)
  • D
    73% (36)
  • E
    2% (1)

Explanation

Group1 is security enabled, role assignment is not allowed. Group1 can be managed. All security enabled groups can be manged by PIM. Note: Groups in Microsoft Entra ID can be classified as either role-assignable or non-role- assignable. Additionally, any group can be enabled or not enabled for use with Microsoft Entra Privileged Identity Management (PIM) for Groups. These are independent properties of the group. Any Microsoft Entra security group and any Microsoft 365 group (except dynamic membership groups and groups synchronized from on-premises environment) can be enabled in PIM for Groups. The group doesn't have to be role-assignable group to be enabled in PIM for Groups. Group2 is security enabled, role assignment is allowed. Group2 can be managed. All security enabled groups can be manged by PIM. Group3 is security enabled, role assignment is allowed. Group3 can be managed. All security enabled groups can be manged by PIM. Group4 is not security enabled. https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/concept-

Topics

#Privileged Identity Management#PIM-enabled groups#role-assignable groups#group types

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice