MS-900 Describe Microsoft 365 apps and services Practice Question
Exhibit
Refer to the exhibit.
{
"tenantId": "contoso.onmicrosoft.com",
"displayName": "Contoso",
"roles": [
{
"roleName": "User Administrator",
"assignments": [
{
"principalId": "user1@contoso.com",
"assignmentType": "Active"
}
]
},
{
"roleName": "Global Administrator",
"assignments": [
{
"principalId": "user2@contoso.com",
"assignmentType": "Eligible"
}
]
}
]
}Refer to the exhibit. The JSON shows Microsoft Entra ID role assignments using Privileged Identity Management (PIM). Which statement about user2@contoso.com is correct?
⚠ Common exam trap
Test-takers frequently confuse 'eligible assignment' with 'no assignment' or 'permanent assignment,' failing to recognize that PIM requires activation for eligible roles, which is a core concept tested in MS-900.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
user2 must activate the Global Administrator role before using it
The JSON shows that user2@contoso.com has an eligible assignment for the Global Administrator role via Microsoft Entra ID PIM. In PIM, an eligible assignment means the user must activate the role (e.g., through the PIM portal or API) before gaining administrative privileges. The JSON snippet includes a property like "assignmentType": "Eligible" (implied by the context), which requires activation to elevate permissions temporarily.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
user2 is not assigned any administrative role
Why it's wrong here
The JSON shows that user2 has an eligible assignment for the Global Administrator role. This is a role assignment—it is not 'no role.' The assignment type is 'Eligible,' meaning user2 is listed as a potential holder of that administrative role, but the role is not active until activated. So the statement that user2 is not assigned any administrative role is factually incorrect because the assignment exists in Entra ID even if not yet activated.
- ✗
user2 cannot access any administrative features
Why it's wrong here
While an eligible Global Administrator does not have immediate access to administrative features, they are not permanently barred from them. User2 can initiate an activation request in Privileged Identity Management (PIM), and once approved/activated (with MFA and justification if required), they will gain the full permissions of Global Administrator for the duration of the activation. Therefore, 'cannot access any administrative features' is too absolute—eligible users can access them after a deliberate activation step.
- ✓
user2 must activate the Global Administrator role before using it
Why this is correct
Correct. In Microsoft Entra ID (Azure AD) Privileged Identity Management, an 'Eligible' assignment does not confer active permissions. User2 must first activate the Global Administrator role—typically by performing MFA, providing business justification, and possibly receiving approval—before they can use any Global Administrator privileges. This time-bound activation is a core security feature that reduces standing admin access and enforces just-in-time access.
- ✗
user2 is permanently assigned the Global Administrator role
Why it's wrong here
The assignment shown in the JSON is explicitly 'Eligible,' not 'Active.' An active assignment would grant permanent or long-term administrative rights immediately, but an eligible assignment requires activation each time and is usually time-limited. Calling it 'permanently assigned' misrepresents the PIM model, where eligible roles are idle until activated and then expire according to the activation duration policy.
Go deeper
Related to this question
Learn chapter
Entra ID Access Reviews
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.