AZ-500 Secure identity and access Practice Question
Your company wants to implement a least-privilege model for administrative roles in Microsoft Entra ID. Which TWO features should you use?
⚠ Common exam trap
Test-takers frequently confuse Azure RBAC roles (which manage Azure resources) with Microsoft Entra ID roles (which manage directory objects), leading them to incorrectly select Azure RBAC roles as a feature for Entra ID least-privilege administration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Custom roles in Microsoft Entra ID
Custom roles in Microsoft Entra ID (option B) are correct because they let you define a precise set of directory permissions (for example, scoping actions like microsoft.directory/users/read) so administrators get only the access they need, which is the essence of least privilege. Privileged Identity Management (option E) is also correct because it enforces just-in-time activation of eligible directory roles with approval, MFA, and time-bound assignments, eliminating standing privileged access. Azure RBAC roles (option A) govern Azure resource-plane access, not Microsoft Entra ID administrative roles, so they don't address the directory role model in scope. Conditional Access policies (option C) control sign-in conditions and access to resources but do not define or limit administrative role permissions. Microsoft Entra B2B external identities (option D) is about collaborating with external users, not about constraining administrative privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure RBAC roles
Why it's wrong here
Azure RBAC roles govern access to Azure resources such as virtual machines, storage, and subscriptions, not to Microsoft Entra ID administrative functions. Since the question targets least privilege for directory roles, assigning Azure RBAC roles would leave directory permissions untouched and fail to constrain who can manage users, groups, or apps. Thus it cannot fulfill the stated requirement.
- ✓
Custom roles in Microsoft Entra ID
Why this is correct
Custom roles in Microsoft Entra ID allow you to define granular permissions by selecting specific tasks, such as reading audit logs or resetting passwords, that aren't combined into built-in roles. This lets you craft a role with exactly the permissions needed for a job, eliminating standing overprivileged access. By assigning such custom roles to principals, you implement least privilege at the directory level.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies control access conditions like device compliance, location, or multi-factor authentication for sign-in events, but they do not alter the permissions granted to a role. While they can reduce risk by restricting when privileged roles are used, they cannot define which specific directory permissions a role holds. Therefore they are not a mechanism for role-based least privilege.
- ✗
Microsoft Entra B2B external identities
Why it's wrong here
Microsoft Entra B2B external identities are designed for inviting guests and external partners to access resources, not for managing internal role permissions. Using B2B would bring in outside users but would not help refine which directory administrative tasks any user can perform. As such, it is unrelated to the goal of least privilege for Microsoft Entra roles.
- ✓
Privileged Identity Management (PIM)
Why this is correct
Privileged Identity Management (PIM) provides just-in-time role activation with time-bound assignments, multi-factor authentication, and approval workflows for elevated roles. It allows you to grant only the necessary permanent access and require users to activate higher privileges on demand, reducing standing privileges. PIM directly supports least privilege by ensuring role members hold elevated permissions only when needed.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.