exam questions

Exam AZ-300 All Questions

View all questions & answers for the AZ-300 exam

Exam AZ-300 topic 16 question 4 discussion

Actual exam question from Microsoft's AZ-300
Question #: 4
Topic #: 16
[All AZ-300 Questions]

Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have an Azure Active Directory (Azure AD) tenant named contoso.com.
A user named Admin1 attempts to create an access review from the Azure Active Directory admin center and discovers that the Access reviews settings are unavailable. Admin1 discovers that all the other Identity Governance settings are available.
Admin1 is assigned the User administrator, Compliance administrator, and Security administrator roles.
You need to ensure that the Admin1 can create access reviews in contoso.com.
Solution: You consent to Azure AD Privileged Identity Management (PIM).
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
PIM essentially helps you manage the who, what, when, where, and why for resources that you care about. Key features of PIM include:
✑ Conduct access reviews to ensure users still need roles
Note: Azure Active Directory (Azure AD) Privileged Identity Management (PIM) is a service that enables you to manage, control, and monitor access to important resources in your organization. This includes access to resources in Azure AD, Azure resources, and other Microsoft Online Services like Office 365 or Microsoft
Intune.
References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ccarlton
Highly Voted 5 years, 3 months ago
'Consent to PIM' does not enable access review feature.
upvoted 10 times
SaurabhAzure
5 years, 2 months ago
thats true...
upvoted 2 times
tartar
4 years, 8 months ago
B is ok
upvoted 2 times
...
...
...
mstm
Highly Voted 4 years, 9 months ago
Please note there are 2 types of access reviews: Access review under Azure AD -> Identity Governance https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review Prerequisites: Azure AD Premium P2 Global administrator or User administrator Purpose: Create access reviews for group members or application access Access review under PIM -> Access review https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-resource-roles-start-access-review Prerequisites: Privileged Role Administrator (and also P2 license, consent to PIM etc.) Purpose: Create access reviews for privileged Azure resource roles As the question is stating "Admin1 discovers that all the other Identity Governance settings are available", I think we are talking about AAD access review type and what's missing there is "Onboarding", probably the scenario is the tenat hasn't been oboarded for access reviews, this is old view but see screenshot for the overview(https://i0.wp.com/wpac.blob.core.windows.net/wpstorage/2019/03/030619_1438_Accessrevie1.png?w=1240&ssl=1). Hence IMO the answer is NO.
upvoted 8 times
...
Showkat
Most Recent 3 years, 5 months ago
The answer is NO, you can create access reviews in PIM, however with proper privileges, you must have either global admin or Privileged role administrator role assigned before you create .
upvoted 1 times
Showkat
3 years, 5 months ago
docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-create-azure-ad-roles-and-resource-roles-review
upvoted 1 times
...
...
sharonh
4 years, 3 months ago
admin1 is a user administrator so he can create access review s: https://docs.microsoft.com/en-us/azure/active-directory/governance/deploy-access-reviews i go with PIM
upvoted 1 times
...
deyc
4 years, 8 months ago
1- Create an access review of groups and applications in Azure AD access reviews Prerequisites Azure AD Premium P2 Global administrator or User administrator 2- Create an access review of Azure AD roles in Privileged Identity Management Pre-requisite: Privileged Role Administrator If I read the question correctly, the access is for groups and apps and not for AD roles... If this is the case, the answer is NO
upvoted 2 times
...
dips31089
4 years, 10 months ago
The answers to all the questions in this series is No. The scenario assumes you are a Global Admin. If you consent to PIM and enable, only you get the Priv Role Admin. Admin 1 wont. Assigning Global Admin role wont work either. They need Priv Role Admin. AD Premium P2 or any license is not needed for creating access reviews.
upvoted 2 times
...
xofowi5140
4 years, 10 months ago
Before you can begin using AAD PIM, you’ll need to purchase a license that includes the capability. - There is no Info about the Azure AD license. Upon opening AAD PIM for the first time, you’ll receive a consent page as seen below. The consent process requires confirmation of the user’s identity using Azure MFA. If the user isn’t enabled for it, it will be configured at this point.
upvoted 1 times
...
Harkonnen
4 years, 10 months ago
The answer is INCORRECT. First, the concept of consenting is no where documented. Check https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-getting-started. Nothing about consenting. What you DO need is the following (from the same source above): To use Privileged Identity Management, your directory must have one of the following paid or trial licenses: Azure AD Premium P2 Enterprise Mobility + Security (EMS) E5 Microsoft 365 Education A5 Microsoft 365 Enterprise E5 The correct answer is a couple of questions below, which is to purchase a P2 license.
upvoted 3 times
xofowi5140
4 years, 10 months ago
https://journeyofthegeek.com/2018/05/29/exploring-azure-ad-privileged-identity-management-pim-part-2-setup/
upvoted 1 times
...
...
gboyega
4 years, 10 months ago
B is the correct answer
upvoted 7 times
praveen97
4 years, 10 months ago
Answer is NO since Privileged Identity requires 'Privileged Role Administrator' role to create Access Reviews. I have tested this in the lab. See the Pre-requisites provided in the below article before creating Access Reviews. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-start-security-review#prerequisites
upvoted 6 times
...
...
azureexaminer
4 years, 11 months ago
Enable Privileged Identity Management As part of the planning process, you must first CONSENT to and enable Privileged Identity Management by following our start using Privileged Identity Management article. Enabling Privileged Identity Management gives you access to some features that are specifically designed to help with your deployment. (https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-deployment-plan)
upvoted 1 times
azureexaminer
4 years, 11 months ago
ignore my comment above. i just reread that all ID settings are available which indicates that ID is already in place.
upvoted 1 times
...
magpi
4 years, 9 months ago
I fell you are right. You have to augment your privileges and enable User Administrator role.
upvoted 1 times
...
...
Abhiatms02
4 years, 11 months ago
Privileged Identity Management (PIM) to create access reviews for "privileged Azure AD" roles. So No.
upvoted 2 times
...
Prash85
5 years ago
To create access review PIM should be enabled which is why the answer is correct.
upvoted 2 times
...
frafra
5 years ago
YES - correct to use Access Review you need to be Global Administrator or User Administrator
upvoted 3 times
...
babacandy
5 years ago
Solution Answer is confusing. To create access review a user should be in "Privileged Role Administrator" role. Reference : https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-start-security-review
upvoted 2 times
...
kishoreg
5 years, 2 months ago
"Conduct access reviews to ensure users still need roles" its clearly written
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...