AZ-500 Secure identity and access Practice Question
You need to assign the 'Security Administrator' role in Microsoft Entra ID to a user named User1. The role assignment must be eligible, and User1 must provide a justification when activating the role. What should you use?
⚠ Common exam trap
Test-takers frequently confuse direct role assignment (which is permanent and active) with PIM's eligible assignment (which is time-bound and requires activation), leading them to choose Option A instead of B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Identity Management (PIM)
Privileged Identity Management (PIM) in Microsoft Entra ID is the only service that supports time-bound, eligible role assignments with activation justification. By configuring a PIM policy for the Security Administrator role, you can require User1 to provide a business justification before the role is activated for a specified duration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Direct role assignment in Microsoft Entra ID roles and administrators
Why it's wrong here
Direct role assignment grants the Security Administrator role as a permanent, active assignment in Microsoft Entra ID. This method bypasses PIM's activation workflow, so there is no time-bound activation, no justification, and no approval requirement. If the scenario requires just-in-time access or compliance approval, direct assignment fails to meet that requirement even though it is a valid way to assign Microsoft Entra ID roles.
- ✓
Privileged Identity Management (PIM)
Why this is correct
Privileged Identity Management (PIM) lets you assign the Security Administrator role as 'eligible' rather than 'active'. The member then activates the role when needed, specifying a business justification and, if configured, obtains approval from designated approvers. This provides just-in-time, time-bound access with full audit logs, satisfying the requirement to assign the role securely and with least privilege.
- ✗
Global Administrator role with custom activation policy
Why it's wrong here
Global Administrator is a built-in, highly privileged Microsoft Entra ID role that implicitly includes all permissions, including Security Administrator. Assigning it to a user who only needs security management is a violation of least privilege, regardless of whether activation policies are customized. Moreover, PIM activation policies are role-specific; you cannot use a 'custom activation policy' to carve out only Security Administrator permissions from the Global Administrator role.
- ✗
User Administrator role with access reviews
Why it's wrong here
User Administrator is limited to managing users, groups, and support tickets; it does not have permission to assign any administrative role in Microsoft Entra ID. Access reviews merely attest existing role assignments or remove stale ones, but they cannot be used as a mechanism to initially assign the Security Administrator role. Therefore, this approach lacks both the required authorization and the capability to grant the role.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.