nerdexam
Microsoft

SC-300 · Question #81

You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table. Which objects can you add as eligible in Azure AD Privileged Identity Management (PIM)…

The correct answer is B. User1 and Guest1 only. You cannot assign service principals as eligible to Azure AD roles, Azure roles, and Privileged Access groups but you can grant a time limited active assignment to all three. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-

Submitted by emma.c· Mar 6, 2026Plan and implement identity governance

Question

You have an Azure Active Directory (Azure AD) tenant that contains the objects shown in the following table. Which objects can you add as eligible in Azure AD Privileged Identity Management (PIM) for an Azure AD role?

Exhibit

SC-300 question #81 exhibit

Options

  • AUser1, Guest1, and Identity1
  • BUser1 and Guest1 only
  • CUser1 only
  • DUser1 and Identity1 only

How the community answered

(36 responses)
  • A
    14% (5)
  • B
    75% (27)
  • C
    3% (1)
  • D
    8% (3)

Explanation

You cannot assign service principals as eligible to Azure AD roles, Azure roles, and Privileged Access groups but you can grant a time limited active assignment to all three. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-

Topics

#PIM#eligible assignments#Azure AD roles#managed identity

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice