AZ-500 Manage identity and access Practice Question
A privileged administrator should activate the Security Administrator role only for approved work and for a limited time. What should be configured?
⚠ Common exam trap
Many candidates confuse permanent active assignments (Option A) with eligible assignments, mistakenly thinking that permanent assignment is sufficient if the user is trusted, but the question explicitly requires 'limited time' activation, which only PIM can enforce.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Eligible assignment with activation controls in Privileged Identity Management
Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure eligible assignments for roles like Security Administrator. This means the user must activate the role on demand, with time-bound activation controls (e.g., maximum activation duration, approval, MFA), ensuring the role is used only for approved work and for a limited time. This directly meets the requirement of just-in-time (JIT) access and temporary activation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Permanent active assignment in Microsoft Entra ID
Why it's wrong here
A permanent active assignment grants the privileged administrator continuous, standing access to the security role in Microsoft Entra ID, never requiring an activation step. This bypasses just-in-time controls and increases the risk of credential abuse, as the high-privilege permissions are always available. It therefore fails to meet the requirement that the administrator must 'activate' security only when needed.
- ✓
Eligible assignment with activation controls in Privileged Identity Management
Why this is correct
An eligible assignment in Privileged Identity Management (PIM) allows the administrator to activate the security role on demand for a limited time, with activation controls such as MFA, business justification, approval workflows, and a maximum duration. This provides just-in-time privileged access, ensuring the security role is not permanently active and its permissions are only used after successful activation. This directly satisfies the requirement.
- ✗
Owner role at the subscription root
Why it's wrong here
Assigning the Owner role at the subscription root grants broad administrative control over all Azure resources in that subscription, but it is not a security-specific role in Microsoft Entra ID and does not involve any activation process. It provides permanent, high-level access rather than time-bound, approved activation, and it typically includes permissions beyond those needed for security administration. Therefore it does not meet the requirement for activating security.
- ✗
Conditional Access session persistence
Why it's wrong here
Conditional Access session persistence controls how long an authenticated session remains valid, such as keeping a user signed in after a successful login, but it does not assign or activate any privileged identity. It cannot grant the security role or provide activation controls like approval or justification; it only affects session lifetime. As a result, it is irrelevant to the stated requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.