exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 32 discussion

Actual exam question from Microsoft's AZ-500
Question #: 32
Topic #: 2
[All AZ-500 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant that contains the users shown in the following table.

In Azure AD Privileged Identity Management (PIM), the Role settings for the Contributor role are configured as shown in the exhibit. (Click the Exhibit tab.)

You assign users the Contributor role on May 1, 2019 as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
References:
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-resource-roles-assign-roles

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hang10z
Highly Voted 4 years, 2 months ago
The answer is YES, YES, NO. MFA Disabled/Enabled means nothing, its there to trick you. That is for 0365 only "Basic" MFA which wouldn't be in use at this point since in order to use PIM you must have EMS E5 licenses/P2 AD so those MFA enable/disabled settings are ignored. They would just get an MFA enrollment wizard/prompt to setup their phone first.
upvoted 102 times
rgullini
4 years, 1 month ago
MFA disabled/enabled means nothing if you have "Security defaults" enabled in Azure AD. If Security Defaults" are disabled, then the MFA configuration applies.
upvoted 6 times
...
abcd1234000
3 years, 8 months ago
Thanks for great explanation!
upvoted 2 times
...
Startkabels
4 years, 2 months ago
Could be, our company has that configuration and my own MFA status is disabled when checking from AAD > Security > MFA > Additional cloud-based MFA settings. This link takes you to https://account.activedirectory.windowsazure.com/ where you can find MFA settings per user where MFA is disabled for all our users. So I would go with you and say that using PIM which requires an AAD P2 license ignores this setting
upvoted 1 times
...
OhBee
4 years, 2 months ago
I think you might be overthinking this. If MFA is disabled, we must assume that the user has not yet even registered to it. So he must register first. Now if asking for registration and then allowing them in is considered as a YES by MS, I have no idea...but I would go with NO on the first one.
upvoted 1 times
...
...
Narragr
Highly Voted 4 years, 3 months ago
User3 cannot because his active right is expired on the 15th June 2019
upvoted 28 times
Geeky93
4 years, 3 months ago
How can User2 use contributor role if he has MFA disabled ? For me it seems to be No No NO
upvoted 8 times
sureshatt
4 years, 2 months ago
MFA status for user DOES NOT MATTER (for PIM, Conditional Access Control and Identity Protection). That is, PIM, Conditional Access Control and Identity Protection will prompt to setup MFA regardless the user MFA status.
upvoted 16 times
...
...
gcpbrig01
4 years, 3 months ago
also user1 can't activate the role since activation requires MFA and its is disabled for the user and user2 is role activated when logged in on May 15, 2019. No, Yes, No
upvoted 26 times
LJack
4 years, 3 months ago
Agree, no yes no
upvoted 8 times
...
...
...
SofiaLorean
Most Recent 3 months ago
Yes, Yes, No?
upvoted 1 times
...
ITFranz
7 months, 2 weeks ago
To support the answer #2. Microsoft Entra PIM for Azure resources provides two distinct assignment types: Eligible assignments require the member to activate the role before using it. Administrator may require role member to perform certain actions before role activation, which might include performing a multi-factor authentication (MFA) check, providing a business justification, or requesting approval from designated approvers. Active assignments don't require the member to activate the role before usage. Members assigned as active have the privileges assigned ready to use. This type of assignment is also available to customers that don't use Microsoft Entra PIM. https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-resource-roles-assign-roles Answer: Yes, YES, NO
upvoted 3 times
Hot_156
3 months, 3 weeks ago
N - User 1 has MFA disabled. PIM won't prompt the user to register as CA does. Y - The role is already enabled N - Active assignment already expired
upvoted 1 times
Hot_156
3 months, 1 week ago
Y - PIM and CA prompt users to register for MFA! Identity Protection DOESNT! Y - The Role is already enabled N - Active assignment already expired
upvoted 1 times
...
...
...
AZ500Xmen
8 months, 3 weeks ago
Yes Yes No. MFA doesn't matter here. User 3 cannot activate PIM because it has expired. A user cannot have both Active and Eligible assignments, so after 15 June, User 3 has no PIM roles since active assignments which it was given, expires 1st June.
upvoted 1 times
...
ch23rr
10 months, 1 week ago
the answer is N Y N.
upvoted 4 times
...
pentium75
10 months, 2 weeks ago
Yes, Yes, No. The per-user MFA setting is completely irrelevant.
upvoted 1 times
...
AZ5002023
1 year, 6 months ago
YYY mfa is disabled but he can activate it when he activate the role User3 the activate's state expired , but the question here is to ACTIVATE NOT USE like the second question
upvoted 5 times
...
wardy1983
1 year, 7 months ago
YES, YES, NO. MFA Disabled/Enabled means nothing, its there to trick you. That is for 0365 only "Basic" MFA which wouldn't be in use at this point since in order to use PIM you must have EMS E5 licenses/P2 AD so those MFA enable/disabled settings are ignored. They would just get an MFA enrollment wizard/prompt to setup their phone first.
upvoted 4 times
...
JunetGoyal
1 year, 7 months ago
YEs,yes, no. User 3 active role expire after a month! so on june 15 he cannot active . User 2 has active assignment user1 is eligible can activate
upvoted 3 times
...
heatfan900
1 year, 9 months ago
IT CLEARLY STATES MFA FOR ACTIVATION OF ELIGIBLE AND MFA FOR ACTIVE ASSIGNMENTS. N,N,Y
upvoted 1 times
Mnguyen0503
1 year, 5 months ago
You're incorrect. MFA for active assignment is only applied to the admin assigning the active role, there's no "activation" required for the admins receiving those assignments.
upvoted 1 times
...
...
Yesvanth1
1 year, 11 months ago
Answers are correct - YYY: Box-3: After the active role is expired on May 30th, only the users active access expired. The user is still eligible for 2 more months, meaning the user can activate it on June15th.
upvoted 6 times
...
Tweety1972
2 years, 1 month ago
Assigned the 1st of May. On the 1st of June the Active Assignments are expired. On the 1st of August the Eligible Assignments are expired too. User1 has an Eligible Assignment so he/she can activate his/her account -> Yes User2 has an Active Assignment so he/she can use his/her account -> Yes User3 has an Active Assignment which was expire after 1 months. So he/she has no longer access to this role -> No
upvoted 6 times
...
pekay
2 years, 2 months ago
YES, YES NO.
upvoted 3 times
...
majstor86
2 years, 3 months ago
Yes Yes No
upvoted 6 times
...
student9k
2 years, 3 months ago
Approvers are not able to approve their own role activation requests. https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/azure-ad-pim-approval-workflow
upvoted 1 times
...
samimshaikh
2 years, 4 months ago
1. Yes, can activate because eligible 2. Yes, Can use it because already an active assignment 3. No, f a user's Privileged Identity Management (PIM) active assignment expires, the user will lose their elevated privileges and will no longer be able to perform privileged actions within the Azure AD environment.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...