Drag steps to the numbered slots on the right, or tap a step then tap a slot.
AZ-500 Manage identity and access Practice Question
Drag and drop the steps to configure Azure AD Privileged Identity Management (PIM) for a role into the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Step 1: Enable PIM, Step 2: Select roles, Step 3: Configure settings, Step 4: Assign users as eligible
PIM requires enabling the service first, then selecting roles, configuring settings, and finally assigning users as eligible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Enable PIM, Step 2: Select roles, Step 3: Configure settings, Step 4: Assign users as eligible
Why this is correct
Enabling PIM first is mandatory because PIM is an Azure AD service that must be activated before any role management can occur; selecting roles next determines which directory roles will be governed by just-in-time access, then configuring settings defines activation requirements such as MFA, approval, and duration, and finally assigning users as eligible grants them the ability to activate those roles on demand. This order respects the dependency that service activation precedes role selection, which precedes role-specific configuration, which precedes user assignment.
- ✗
Step 1: Select roles, Step 2: Configure settings, Step 3: Enable PIM, Step 4: Assign users as eligible
Why it's wrong here
Attempting to select roles before enabling PIM is impossible because the PIM blade and its role management interface are provisioned only after you activate PIM in Azure AD; configuring settings even later in this sequence is premature because those role-specific settings cannot exist until roles are actually chosen. This order incorrectly assumes you can define the scope of PIM governance before the service itself is initialized, whereas PIM must be the entry point to any role selection or configuration.
- ✗
Step 1: Assign users as eligible, Step 2: Enable PIM, Step 3: Select roles, Step 4: Configure settings
Why it's wrong here
Assigning users as eligible first is invalid because an eligible assignment is a PIM-specific concept that requires PIM to be enabled and at least one Azure AD role to be selected as a target, and it also depends on the role's activation settings being configured to determine how users will request activation. Without the role and service in place, there is no assignment resource for the user to hold, so this step cannot logically come first.
- ✗
Step 1: Configure settings, Step 2: Select roles, Step 3: Enable PIM, Step 4: Assign users as eligible
Why it's wrong here
Starting with configuring settings is incorrect because PIM's settings are scoped to each selected role — you cannot define activation rules before you have chosen which roles will be managed — and the PIM service itself must be enabled before any settings blade is accessible. This order mistakenly treats configuration as a global prerequisite rather than a role-specific step that follows role selection and service activation.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 194-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.