exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 50 discussion

Actual exam question from Microsoft's AZ-500
Question #: 50
Topic #: 2
[All AZ-500 Questions]

You have an Azure subscription that contains the users shown in the following table.

Which users can enable Azure AD Privileged Identity Management (PIM)?

  • A. User2 and User3 only
  • B. User1 and User2 only
  • C. User2 only
  • D. User1 only
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
teehex
Highly Voted 4 years, 1 month ago
The given answer is incorrect. This question is asking who can enable PIM? To enable PIM there are 3 main steps: - Login to Azure Portal as a Global Admin. - Consent to PIM - You are asked to verify your identity with MFA. If you haven't set up MFA yet you are asked to complete MFA setup before you can consent PIM. Reference: https://github.com/MicrosoftDocs/azure-docs/commit/755069f4ff7430f739b1933dc082dffe9b6d564f#diff-38273a45d682dbc4e8ca5cb8548a045af63218005855ec067b0707aaa9d406f0 In this case, User2 can enable Azure PIM. How about user3? Yes it can because when MFA is asked the MFA state is changed to Enabled and User3 just needs to complete MFA setup before it can consent and enable PIM. The correct answer is A - User2 and User3 only.
upvoted 102 times
153a793
8 months, 3 weeks ago
This elaboration is perfect. but, given the state of MFA in question, only user 2 can do it.
upvoted 1 times
...
...
fabianotrd
Highly Voted 4 years, 3 months ago
Only global admin with MFA enabled can configure PIM
upvoted 37 times
OpsecDude
2 years, 9 months ago
You don't need MFA to enable it. Indeed, I have a brand new fresh AAD and the first thing I did was enable PIM. Another thing: Consent is NO LONGER needed. You just enable it, period.
upvoted 11 times
pentium75
11 months ago
You don't need MFA enabled PER USER (!) to use MFA.
upvoted 1 times
...
...
Outbreak
3 years, 11 months ago
Source?
upvoted 4 times
...
...
LHU
Most Recent 1 month ago
Selected Answer: A
As I understand it; The fact User1 is the owner of a subscription within a tenant has nothing to do with what's going on in the Azure Tenant itself - like the PIM configuration. User1 lacks the privileges to handle those. Therefore, answer A.
upvoted 1 times
...
Strive_for_greatness_kc
1 year, 5 months ago
We no more need consent to enable PIM, so all global admin regardless of their MFA status can activate PIM
upvoted 3 times
...
ESAJRR
1 year, 9 months ago
Selected Answer: A
A. User2 and User3 only
upvoted 1 times
...
ArchitectX
1 year, 9 months ago
Selected Answer: A
right answer
upvoted 1 times
...
majstor86
2 years, 3 months ago
Selected Answer: A
A. User2 and User3 only
upvoted 2 times
...
OpsecDude
2 years, 9 months ago
Selected Answer: A
It is A nowadays. Still, that GA with no MFA is a total liability.
upvoted 3 times
...
Nik2Quik
2 years, 11 months ago
Selected Answer: A
its A as teehex explained, its asking who can enable
upvoted 1 times
...
TtotheA2021
2 years, 11 months ago
Selected Answer: A
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-deployment-plan
upvoted 1 times
...
tnagy
2 years, 11 months ago
Selected Answer: A
Totally agree with Teehex's explanation
upvoted 2 times
...
Alessandro365
3 years ago
Selected Answer: A
A is correct answer.
upvoted 1 times
...
HazemSbaih
3 years ago
A- is Correct : https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim- deployment-plan
upvoted 1 times
...
feln
3 years ago
Selected Answer: A
You need global admin to enable PIM, MFA can be set up by user3 while enabling PIM...
upvoted 6 times
...
Eltooth
3 years, 3 months ago
Selected Answer: A
Only global admin can first enable PIM.
upvoted 2 times
...
siobhan1
3 years, 3 months ago
## In today's exam 03/12/2022
upvoted 2 times
...
gc12345
3 years, 4 months ago
Ans:User2 & User3. Considering by ...1)they are Global admin. 2)user2 already enforced with MFA ,user3 can opt for MFA when request PIM 3) refer this https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-require-mfa Hope there P2 licensed user above all of this. I can see many questions here are not providing complete information.It leads us to take wrong answer. Its not testing our knowledge, it is cheating...lol
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...