exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 107 discussion

Actual exam question from Microsoft's AZ-500
Question #: 107
Topic #: 2
[All AZ-500 Questions]

You have an Azure subscription linked to an Azure AD tenant named contoso.com. Contoso.com contains a user named User1 and an Azure web app named App1.

You plan to enable User1 to perform the following tasks:

• Configure contoso.com to use Microsoft Entra Verified ID.
• Register App1 in contoso.com.

You need to identify which roles to assign to User1. The solution must use the principle of least privilege.

Which two roles should you identify? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

  • A. Authentication Policy Administrator
  • B. Authentication Administrator
  • C. Cloud App Security Administrator
  • D. Application Administrator
  • E. User Administrator
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
xcapell
Highly Voted 2 years ago
AD. https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable-credentials-configure-tenant Ensure that you have the global administrator or the authentication policy administrator permission for the directory you want to configure. If you're not the global administrator, you need the application administrator permission to complete the app registration including granting admin consent.
upvoted 12 times
...
8de3321
Most Recent 7 months ago
Selected Answer: CD
The answer is Cloud App Administrator and Application Administrator. This exact same question is available in the practice assessment on the leran.Microsoft website and they also show you the answer alongside the reason for the answer. Please check and confirm. Thank you!
upvoted 1 times
Hot_156
4 months ago
Share the link. Are you saying you can configure Microsoft Verify ID with Cloud app security admin?
upvoted 1 times
...
...
Jimmy500
1 year ago
Prerequisites You need an Azure tenant with an active subscription. If you don't have an Azure subscription, create one for free. Ensure that you have the Global Administrator or the authentication policy administrator permission for the directory you want to configure. If you're not the Global Administrator, you need the application administrator permission to complete the app registration including granting admin consent. Ensure that you have the contributor role for the Azure subscription or the resource group where you are deploying Azure Key Vault. Ensure that you provide access permissions for Key Vault. For more information, see Provide access to Key Vault keys, certificates, and secrets with an Azure role-based access control. https://learn.microsoft.com/en-us/entra/verified-id/verifiable-credentials-configure-tenant AD
upvoted 2 times
...
Pamban
1 year, 1 month ago
Selected Answer: AD
Answers: AD Link: https://learn.microsoft.com/en-us/entra/verified-id/verifiable-credentials-configure-tenant
upvoted 2 times
...
crutester
1 year, 4 months ago
Selected Answer: AD
AD. https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable-credentials-configure-tenant Ensure that you have the global administrator or the authentication policy administrator permission for the directory you want to configure. If you're not the global administrator, you need the application administrator permission to complete the app registration including granting admin consent.
upvoted 1 times
...
OrangeSG
1 year, 8 months ago
Selected Answer: AD
To enable User1 to perform the tasks, you should assign the following roles: - Authentication Policy Administrator: This role is required to configure the tenant for Microsoft Entra Verified ID. The user needs to have the global administrator or the authentication policy administrator permission for the directory they want to configure. - Application Administrator: This role is required to register an application in Microsoft Entra ID. If User1 is not the global administrator, they need the application administrator permission to complete the app registration including granting admin consent. Reference Configure your tenant for Microsoft Entra Verified ID https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable-credentials-configure-tenant
upvoted 3 times
...
TheProfessor
1 year, 9 months ago
Selected Answer: AD
Correct Answer: A, D
upvoted 1 times
...
BigShot0
1 year, 9 months ago
Selected Answer: AD
A - Authentication Policy Administrator - Can create and manage the authentication methods policy, tenant-wide MFA settings, password protection policy, and verifiable credentials. D - Application Administrator - Can create and manage all aspects of app registrations and enterprise apps. NOT B - Authentication Administrator - Can access to view, set and reset authentication method information for any non-admin user. You are setting policy for the Org, not managing users. https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference
upvoted 2 times
...
heatfan900
1 year, 10 months ago
Prerequisites You need an Azure tenant with an active subscription. If you don't have an Azure subscription, create one for free. Ensure that you have the global administrator or the authentication policy administrator permission for the directory you want to configure. If you're not the global administrator, you need the application administrator permission to complete the app registration including granting admin consent. • Configure contoso.com to use Microsoft Entra Verified ID. >>authentication policy administrator • Register App1 in contoso.com >>application administrator
upvoted 1 times
...
alfaAzure
1 year, 10 months ago
Selected Answer: AD
AD is correct. https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/verifiable-credentials-configure-tenant
upvoted 1 times
...
_fvt
1 year, 10 months ago
Selected Answer: AD
Given answer is correct
upvoted 1 times
...
Self_Study
1 year, 10 months ago
Selected Answer: BD
The correct answer is B and D. Authentication Administrator and Application Administrator.
upvoted 1 times
pentium75
11 months ago
Authentication Administrator has too much privilege
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...