Courseiva
Secure identity and access →mediumMultiple Select

AZ-500 Secure identity and access Practice Question

Which TWO actions should you take to implement a zero-trust identity model using Microsoft Entra ID? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse password hash synchronization (a hybrid sync tool) with a security control, or they mistakenly think password expiration policies are still a recommended zero-trust practice, when in fact zero-trust focuses on real-time verification and risk-based policies rather than static password rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Privileged Identity Management to require approval for role activation

Privileged Identity Management (PIM) enforces just-in-time (JIT) access by requiring approval for role activation, which aligns with the zero-trust principle of 'never trust, always verify' by eliminating standing privileges. Option E is correct because Conditional Access policies that require MFA and device compliance enforce continuous verification of user identity and device health before granting access, a core tenet of zero-trust identity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure password expiration policies to force frequent changes

    Why it's wrong here

    Password expiration policies are a legacy credential-lifecycle control, not a zero-trust control. Zero trust centers on continuously verifying identity, device health, and context for every request; forcing frequent password changes fails to do that and actually encourages predictable, weak password patterns. Microsoft's security guidance aligns with NIST recommendations that periodic forced expirations be abandoned in favor of modern, risk-based authentication such as MFA and Conditional Access. The only time a password change matters in zero trust is when compromise is detected, which is a reactive, not proactive, control.

  • ✗

    Enable password hash synchronization to Microsoft Entra ID

    Why it's wrong here

    Password hash synchronization (PHS) simply synchronizes on-premises Active Directory password hashes to Microsoft Entra ID so that sign-ins can be authenticated against the same credential in the cloud. PHS is an identity-connectivity feature that enables hybrid users to access cloud resources, but it does not itself enforce zero-trust principles like verify explicitly or use least privilege. Zero trust requires authentication to be challenged based on real-time signals—user, device, location, and risk—whereas PHS merely makes the same static credential available for authentication without any policy enforcement.

  • ✓

    Configure Privileged Identity Management to require approval for role activation

    Why this is correct

    Configuring Privileged Identity Management (PIM) to require approval for role activation enforces just-in-time (JIT) access, a core zero-trust tenet. With PIM, a role is eligible but not active; the user must request activation for a specific time window, and an approver must grant it, which limits standing privileges and reduces the attack surface. This also provides auditing and time-bound access, ensuring that privileged roles are never permanently available and that every activation is specifically authorized. This aligns with 'use least privilege access' and 'verify explicitly' because the approval step adds an explicit verification of requestor legitimacy.

  • ✗

    Assign permanent Global Administrator roles to IT staff

    Why it's wrong here

    Assigning permanent Global Administrator roles to IT staff violates the zero-trust principle of least privilege and 'assume breach.' Permanent roles grant standing, unrestricted access to all Microsoft Entra ID and tenant-wide resources; if a Global Administrator account is compromised, the attacker inherits that persistent, high-privilege access without any additional verification. Zero trust demands that access be explicitly verified and time-bound, not statically assigned. Instead, administrators should use PIM to activate elevated roles only when needed, with approval and just-in-time limits.

  • ✓

    Implement Conditional Access policies that require MFA and device compliance

    Why this is correct

    Conditional Access policies that require MFA and device compliance are a direct implementation of zero trust's 'verify explicitly' principle because they evaluate real-time signals at authentication time. MFA proves user identity, while device compliance (via Intune MDM or Windows health attestation) confirms that the device is trusted and meets security baselines before access is granted. These policies can also incorporate risk, location, and session context, enabling continuous policy enforcement even after initial access. This is a primary Microsoft Entra ID control for enforcing identity and device trust under the zero-trust model.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.