20+ practice questions focused on Manage identity and access — one of the most tested topics on the Microsoft Azure Security Engineer Associate AZ-500 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Manage identity and access PracticeA company uses Azure AD Privileged Identity Management (PIM) for the Global Administrator role. They have configured the role activation to require approval from a specific security group. When a user attempts to activate the role, they are immediately approved without any approval request being sent. The user is a member of the same security group that is configured as the approver. What is the most likely cause?
Explanation: Microsoft Entra PIM explicitly prevents users from approving their own activation requests, even if they are members of the approver group. The scenario describes immediate activation with no approval request being sent, which indicates that the approval requirement is not being enforced. The most likely cause is that the PIM approval policy has not been activated for the Global Administrator role, so no approval workflow is triggered.
A company uses Azure AD Privileged Identity Management (PIM) for the Security Administrator role. They want the activation of this role to require approval from a specific group of senior security engineers before the role becomes active. They also want the approvers to receive an email notification when an activation request is submitted. Which PIM configuration must be set?
Explanation: Microsoft Entra PIM requires the 'Require approval to activate' setting to enforce that activation requests for a role must be approved by designated approvers before the role becomes active. This setting also automatically triggers email notifications to the configured approvers when a request is submitted, fulfilling both the approval and notification requirements.
A company uses Azure AD Privileged Identity Management (PIM) to manage access to Azure resources. They want to enforce that when a user activates the Contributor role for a specific resource group, they must provide a ticket number as justification and the activation is limited to 4 hours. Which PIM settings should they configure?
Explanation: Microsoft Entra PIM allows role settings to be configured at the resource group scope. By editing the role settings for the Contributor role under that specific resource group, you can require justification (e.g., a ticket number) and set a maximum activation duration (e.g., 4 hours). These settings apply only when users activate the role for that resource group via PIM.
A company uses Azure AD with Premium P2 licenses. They want to require that all new users register for Azure Multi-Factor Authentication (MFA) within 14 days of their first sign-in. If they do not register, they should be denied access to all cloud applications until registration is completed. Which Azure AD feature should they configure?
Explanation: The requirement to enforce MFA registration within a specific time frame and block access until registration is complete is achieved by configuring a Conditional Access policy targeting the 'Register security information' (MFA registration) user action. This policy can require users to register for MFA and, if not completed, deny access to all cloud apps. Microsoft Entra ID P2 licenses are required for Conditional Access.
A company uses Azure AD Privileged Identity Management (PIM) for Azure AD roles. They want to require that when a user activates the Security Administrator role, they must provide a justification and the activation must be approved by a member of a specific security group. Which PIM setting should they configure?
Explanation: Microsoft Entra PIM separates the requirements for activation justification and approval. To require both, you must enable 'Require justification' (so users must type a justification) and 'Require approval to activate' (so an approver from the specified security group must approve the activation). Configuring only A omits the mandatory justification requirement.
+15 more Manage identity and access questions available
Practice all Manage identity and access questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Manage identity and access. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Manage identity and access questions on the AZ-500 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Manage identity and access is tested as part of the Microsoft Azure Security Engineer Associate AZ-500 blueprint. Practicing with targeted Manage identity and access questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free AZ-500 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Manage identity and access is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Manage identity and access practice session with instant scoring and detailed explanations.
Start Manage identity and access Practice →