SC-300 · Question #81
You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table. Which objects can you add as eligible in Azure AD Privileged Identity Management (PIM)…
The correct answer is B. User1 and Guest1 only. You cannot assign service principals as eligible to Azure AD roles, Azure roles, and Privileged Access groups but you can grant a time limited active assignment to all three. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-
Question
You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table. Which objects can you add as eligible in Azure AD Privileged Identity Management (PIM) for an Azure AD role?
Exhibit
Options
- AUser1, Guest1, and Identity1
- BUser1 and Guest1 only
- CUser1 only
- DUser1 and Identity1 only
How the community answered
(36 responses)- A14% (5)
- B75% (27)
- C3% (1)
- D8% (3)
Explanation
You cannot assign service principals as eligible to Azure AD roles, Azure roles, and Privileged Access groups but you can grant a time limited active assignment to all three. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-
Topics
Community Discussion
No community discussion yet for this question.
