exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 2 question 59 discussion

Actual exam question from Microsoft's AZ-500
Question #: 59
Topic #: 2
[All AZ-500 Questions]

HOTSPOT -
You have an Azure subscription that contains the Azure Active Directory (Azure AD) resources shown in the following table.

You create the groups shown in the following table.

Which resources can you add to Group5 and Group6? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JBS
Highly Voted 3 years, 8 months ago
Given answers are correct. For Group5, You can add enterprise applications to security groups. (Tested & Verified)
upvoted 45 times
...
orcnylmz
Highly Voted 2 years, 8 months ago
Answer is Group5: User1, Group1, Managed1 Group6: User1 Here is why: https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/concept-learn-about-groups#group-types Members of a security group can include users, devices, other groups, and service principals, which define access policy and permissions. Owners of a security group can include users and service principals. Members of a Microsoft 365 group can only include users.
upvoted 13 times
ITFranz
5 months, 1 week ago
To support answer Group5. you cannot add enterprise applications to a security group that has the membership type of "Assigned". Security groups are used to group users and devices, not applications. The relationship between security groups and enterprise applications works in the opposite direction: Security groups (with assigned membership) can be added to enterprise applications for access control. Users and devices can be assigned to security groups. Enterprise applications can then use these security groups to manage access. This approach allows for more efficient management of application access by grouping users and devices, rather than adding applications to groups. It's important to note that only security groups can be used for this purpose, and they cannot be nested when assigning to enterprise applications
upvoted 2 times
...
basak
1 year, 10 months ago
For Group 5 your answer is wrong. When an app is registered a service principal is created. according to your description service principle can be added in security group. Therefore, App1 also can be added.
upvoted 1 times
...
_fvt
1 year, 10 months ago
App1 is not an App Registration but an Enterprise Application. An Enterprise Application is a Service Principal. So, answer is Group5: User1, Group1, Managed1, App1 Group6: User1
upvoted 15 times
...
...
ca7859c
Most Recent 2 weeks, 3 days ago
Answer is correct You can manage two types of groups in the Microsoft Entra admin center: https://learn.microsoft.com/en-us/entra/fundamentals/concept-learn-about-groups Security groups: Used to manage access to shared resources. Members of a security group can include users, devices, service principals. Groups can be members of other groups, sometimes known as nested groups. See note. Users and service principals can be the owner of a security group. Microsoft 365 groups: Provide collaboration opportunities. Members of a Microsoft 365 group can only include users. Users and service principals can be the owner of a Microsoft 365 group. People outside of your organization can be members of a group. For more information, see Learn about Microsoft 365 Groups.
upvoted 1 times
...
Jimmy500
11 months, 1 week ago
When we create managed identity does not matter user assigned and system assigned it registered as an enterprise application in our tenant and we can add the to them to the security groups. All in all, we can add user assigned, system assigned managed identities, service principals to the security groups as well as users and other security groups, we cannot add Microsoft 365 group to the security groups. From here we can say that for the Box-1 we can choose , User1,Group1,Manged1,App1(this is service principial as question says this has been registered in entra that is why we can add it as well). For the box 2 we can only add User1, we cannot add Service principal, devices, security groups, managed identity to the Microsoft 365 group. Answer will be like this: Box-1 All Box-2 only User1. Regards! Quick not also given answer is corret!
upvoted 5 times
...
Goke282
1 year, 3 months ago
In Azure, you cannot have a device and a user in the same security group. Dynamic groups in Azure Active Directory (Azure AD) can be created for devices or for users, but you can’t create a rule that contains both users and devices. Device membership rules can reference only device attributes1. This means you would need to create separate groups for users and devices if you want to manage them dynamically based on their attributes. If you need to manage devices and users together in some way, you might consider creating separate groups and then using Azure policies or other management tools to apply the necessary controls across those groups. For the above reason, it can be concluded that the answer to Group5 is User1 Only.
upvoted 2 times
pentium75
10 months, 2 weeks ago
"You can’t create a rule that contains both users and devices" yeah but that has not been asked here. Security groups can contain other security groups. A security group with assigned membership can include users, service principals, managed identities, or other security groups.
upvoted 1 times
...
...
Goke282
1 year, 3 months ago
I think the answer is wrong for Group 5 because you cannot have devices and users in the same group. Therefore Group 1 cannot be in Group 5 as the others.
upvoted 1 times
pentium75
10 months, 2 weeks ago
We cannot have "devices and users in the same group" but we can have multiple security groups (one with users, one with devices) in another security group.
upvoted 1 times
...
...
Obama_boy
1 year, 6 months ago
in exam 08/12/23
upvoted 3 times
...
[Removed]
1 year, 9 months ago
You cannot add AppRegistraion to a security group just tested in the lab no option to add to enterprise application is coming up in the list of members
upvoted 1 times
fireb
1 year, 8 months ago
App1 is an Enterprise Application, not an AppRegistration.
upvoted 3 times
...
...
Troublemaker
1 year, 10 months ago
In Exam - 28/7/2023
upvoted 2 times
...
zellck
2 years, 1 month ago
1. User1, Group1, Managed1, and App1 2. User1 only https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/concept-learn-about-groups#group-types - Security: Used to manage user and computer access to shared resources. For example, you can create a security group so that all group members have the same set of security permissions. Members of a security group can include users, devices, other groups, and service principals, which define access policy and permissions. Owners of a security group can include users and service principals. - Microsoft 365: Provides collaboration opportunities by giving group members access to a shared mailbox, calendar, files, SharePoint sites, and more. This option also lets you give people outside of your organization access to the group. Members of a Microsoft 365 group can only include users. Owners of a Microsoft 365 group can include users and service principals.
upvoted 7 times
...
majstor86
2 years, 3 months ago
Correction for Group 5: User1, Group1, Managed1, App1
upvoted 2 times
...
majstor86
2 years, 3 months ago
Group5: User1, Group1, Managed1 Group6: User1
upvoted 2 times
...
Amit3
2 years, 8 months ago
# In EXAM - 01-Oct-2022
upvoted 4 times
...
salmantarik
3 years, 1 month ago
Security groups can be used for either devices or users, but Microsoft 365 Groups can be only user groups. Given answer is correct
upvoted 4 times
...
siobhan1
3 years, 3 months ago
# In exam today 03/12/2022
upvoted 4 times
...
cfsxtuv33
3 years, 5 months ago
Some extra info with an added link. After identifying the resource types of your resources, you must investigate if they can be moved, and the restrictions that are in place. Check your resource types against the move list below. The list shows whether each resource type can be moved between resource groups or between subscriptions: https://docs.microsoft.com/en-us/learn/modules/move-azure-resources-another-resource-group/4-assess-resources For example, these resources can be moved: Azure Storage accounts Azure virtual machines Azure virtual networks These resources can't be moved: Azure Active Directory domain services Azure Backup vaults Azure App Service gateways
upvoted 2 times
...
HananS
3 years, 5 months ago
Unfortunately, you cannot add an application as a member of Azure AD group. https://stackoverflow.com/questions/47762262/add-aad-application-as-a-member-of-a-security-group so the answer is user 1 ,managed1 and group 1 only for the first one
upvoted 2 times
JL15546
3 years, 5 months ago
Sorry HananS. I just tested it and it worked. So, yes, we an app can be added as a member of a AZ AD Security group. Answer is correct.
upvoted 8 times
...
OpsecDude
2 years, 8 months ago
Just like JL15546 says, plus think of the app as a service principal to which roles can be assigned.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...