Courseiva

AZ-500 Secure identity and access Practice Question

Your company wants to implement a least-privilege model for administrative roles in Microsoft Entra ID. Which TWO features should you use?

⚠ Common exam trap

Test-takers frequently confuse Azure RBAC roles (which manage Azure resources) with Microsoft Entra ID roles (which manage directory objects), leading them to incorrectly select Azure RBAC roles as a feature for Entra ID least-privilege administration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Custom roles in Microsoft Entra ID

Custom roles in Microsoft Entra ID (option B) are correct because they let you define a precise set of directory permissions (for example, scoping actions like microsoft.directory/users/read) so administrators get only the access they need, which is the essence of least privilege. Privileged Identity Management (option E) is also correct because it enforces just-in-time activation of eligible directory roles with approval, MFA, and time-bound assignments, eliminating standing privileged access. Azure RBAC roles (option A) govern Azure resource-plane access, not Microsoft Entra ID administrative roles, so they don't address the directory role model in scope. Conditional Access policies (option C) control sign-in conditions and access to resources but do not define or limit administrative role permissions. Microsoft Entra B2B external identities (option D) is about collaborating with external users, not about constraining administrative privileges.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure RBAC roles

    Why it's wrong here

    Azure RBAC roles govern access to Azure resources such as virtual machines, storage, and subscriptions, not to Microsoft Entra ID administrative functions. Since the question targets least privilege for directory roles, assigning Azure RBAC roles would leave directory permissions untouched and fail to constrain who can manage users, groups, or apps. Thus it cannot fulfill the stated requirement.

  • ✓

    Custom roles in Microsoft Entra ID

    Why this is correct

    Custom roles in Microsoft Entra ID allow you to define granular permissions by selecting specific tasks, such as reading audit logs or resetting passwords, that aren't combined into built-in roles. This lets you craft a role with exactly the permissions needed for a job, eliminating standing overprivileged access. By assigning such custom roles to principals, you implement least privilege at the directory level.

  • ✗

    Conditional Access policies

    Why it's wrong here

    Conditional Access policies control access conditions like device compliance, location, or multi-factor authentication for sign-in events, but they do not alter the permissions granted to a role. While they can reduce risk by restricting when privileged roles are used, they cannot define which specific directory permissions a role holds. Therefore they are not a mechanism for role-based least privilege.

  • ✗

    Microsoft Entra B2B external identities

    Why it's wrong here

    Microsoft Entra B2B external identities are designed for inviting guests and external partners to access resources, not for managing internal role permissions. Using B2B would bring in outside users but would not help refine which directory administrative tasks any user can perform. As such, it is unrelated to the goal of least privilege for Microsoft Entra roles.

  • ✓

    Privileged Identity Management (PIM)

    Why this is correct

    Privileged Identity Management (PIM) provides just-in-time role activation with time-bound assignments, multi-factor authentication, and approval workflows for elevated roles. It allows you to grant only the necessary permanent access and require users to activate higher privileges on demand, reducing standing privileges. PIM directly supports least privilege by ensuring role members hold elevated permissions only when needed.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.