exam questions

Exam MS-500 All Questions

View all questions & answers for the MS-500 exam

Exam MS-500 topic 1 question 46 discussion

Actual exam question from Microsoft's MS-500
Question #: 46
Topic #: 1
[All MS-500 Questions]

HOTSPOT -
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users shown in the following table.

The User Administrator role is configured in Azure AD Privileged Identity Management (PIM) as shown in the following exhibit.

You make User4 eligible for the User Administrator role.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BabiBu5
Highly Voted 2 years, 10 months ago
Y,Y,Y https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications
upvoted 44 times
examdj101j
2 years, 2 months ago
The way the question is written is Y, Y, Y as BabiBu5 has noted. The question is worded poorly and you have to assume that they meant to word it the same as the 3rd question which would mean N, N, Y
upvoted 1 times
Dhamus
2 years, 2 months ago
I don't understand, is this question wrong?
upvoted 1 times
...
...
...
djpunky
Highly Voted 2 years, 8 months ago
Wouldn't it be Yes, No Yes? When users activate their role and the role setting requires approval, approvers will receive two emails for each approval: Request to approve or deny the user's activation request (sent by the request approval engine) The user's request is approved (sent by the request approval engine) Also, Global Administrators and Privileged Role Administrators receive an email for each approval: The user's role is activated (sent by Privileged Identity Management) https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications Security Administrator, doesn't have the same access as a PRM https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#security-administrator https://learn.microsoft.com/en-us/azure/active-directory/roles/permissions-reference#privileged-role-administrator
upvoted 10 times
ariania
2 years, 8 months ago
https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications check the table "Role activation request is completed" - it goes to Global Admin, Privileged role Admin and Security Admin.
upvoted 4 times
yoton
2 years, 5 months ago
THIS! Documentation states, "If the Notifications setting is set to Enable," (which it is for this questions) emails are sent when role activation request is completed for the following users Privileged Role Administrator, Security Administrator, and Global Administrator. Wouldn't this make the answer YYY? Ref: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications
upvoted 3 times
...
...
BigDazza_111
2 years, 7 months ago
agreed YNY, global admins do recieve a notification email when users role is activated by Priv Role admin, your link proves this https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications
upvoted 3 times
...
...
czaaa
Most Recent 2 years ago
When users activate their role and the role setting requires approval, approvers will receive two emails for each approval: Request to approve or deny the user's activation request (sent by the request approval engine) The user's request is approved (sent by the request approval engine) Also, Global Administrators and Privileged Role Administrators receive an email for each approval: The user's role is activated (sent by Privileged Identity Management)
upvoted 1 times
...
McMac
2 years ago
User Role activation is pending approval Role activation request is completed PIM is enabled Privileged Role Administrator (Activated) Yes (only if no explicit approvers are specified) Yes* Yes Security Administrator (Activated) No Yes* Yes Global Administrator (Activated) No Yes* Yes
upvoted 1 times
...
GPerez73
2 years, 1 month ago
Y,Y,Y tested in lab
upvoted 4 times
...
Dhamus
2 years, 1 month ago
Y: The global admin can receive notifications by default according to the documentation. Y: The security administrator can receive notifications by default according to the documentation. Y: The Privileged Role Manager will receive notifications only when the appropriate approvers have not been specified. https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications
upvoted 1 times
...
heshmat2022
2 years, 2 months ago
When users activate their role and the role setting requires approval, approvers will receive two emails for each approval: Request to approve or deny the user's activation request (sent by the request approval engine) The user's request is approved (sent by the request approval engine) Also, Global Administrators and Privileged Role Administrators receive an email for each approval:
upvoted 1 times
...
RomanV
2 years, 2 months ago
Correct answer should be Y, Y, Y. Reasons: Privileged Role Administrators receive an email notification when a role activation is pending approval (if no explicit approvers are specified), when a role activation request is completed, and when PIM is enabled. Security Administrators receive an email notification only when a role activation request is completed or when PIM is enabled. They do not receive a notification when a role activation is pending approval. Global Administrators do not receive email notifications when a role activation is pending approval, but they do receive a notification when a role activation request is completed or when PIM is enabled. Read also the last question "User4 REQUESTS activation" & the first 2 questions are "User4 ACTIVATES"
upvoted 1 times
...
GatesBill
2 years, 2 months ago
When we look in the given URL below, we'll see that Global Admin and Security Admin will not receive a mail when the request for activation is still pending. The tricky past in this question is however that User4 "activates" a role thus this still needs to be approved first before activation is completed (THEN the other admins will get a mail). It is indeed a weirdly constructed question as "activates" would still mean "yet activated", but seemingly not in Microsoft terms... https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications#notifications-for-azure-ad-roles
upvoted 1 times
...
Dislexsick
2 years, 4 months ago
Another horribly worded question. Here the trick is "when X activates the role" vs. "when X requests activation of the role" While everyone in comments here seems to be looking deeper and noting that post-approval more emails get sent out I think it's much simpler -- Option A, and B are impossible actions, it's a trick question since they don't activate it directly (Though we as logical people are treating their request, with approval as the indirect activation which it is) tl;dr: User is not activating the role, they are requesting activation of the role, thus A and B aren't things that can even occur in this bad example, and B is correct.
upvoted 6 times
...
Brigg5
2 years, 5 months ago
Y Y N When an activation is completed, Global Admins, Security Admins, and Privileged Role Admins receive a notification. When an activation is pending, only the Privileged Role Admin receives a notification.The last question is a request, not an activation.
upvoted 3 times
rick001
2 years, 5 months ago
Correct. Key is in the REQUEST and not ACTIVATE. Y Y N
upvoted 1 times
ysm
2 years, 3 months ago
But User 3 is Privileged Role Admin
upvoted 1 times
...
...
...
Ksumeet91
2 years, 6 months ago
User Role activation is pending approval Role activation request is completed PIM is enabled Privileged Role Administrator (Activated/Eligible) Yes (only if no explicit approvers are specified) Yes* Yes Security Administrator (Activated/Eligible) No Yes* Yes Global Administrator (Activated/Eligible) No Yes* Yes So, answer is Y,Y,Y
upvoted 1 times
...
JonK
2 years, 6 months ago
N,N,Y is correct! Question 1 is "activates" Question 2 is "activates" Question 3 is "requests" https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications Answer chart pulled from the link above: Privileged Role Administrator (Activated/Eligible): --Role activation is pending approval (only if no explicit approvers are specified): Yes --Role activation request is completed: Yes* --PIM is enabled: Yes Security Administrator (Activated/Eligible): --Role activation is pending approval (only if no explicit approvers are specified): No --Role activation request is completed: Yes* --PIM is enabled: Yes Global Administrator (Activated/Eligible)(Activated/Eligible): --Role activation is pending approval (only if no explicit approvers are specified): No --Role activation request is completed: Yes* --PIM is enabled: Yes
upvoted 4 times
Paul_white
2 years, 5 months ago
The confusion here is, User Activates the role and notification is sent to approver before the role gets activated
upvoted 2 times
...
...
ccadenasa
2 years, 7 months ago
The answer is Y,Y,Y. I did a test in my Lab to double-check the output based on this information > https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications#notifications-for-azure-ad-roles
upvoted 4 times
...
HartMS
2 years, 7 months ago
Y,Y,Y is a correct answer. These admins get a notification when a role is activated, if enable notification tab is set to enabled: Global Administrators Security Administrators Privileged Role Administrator Here is the proof: https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications
upvoted 3 times
...
gaida
2 years, 8 months ago
If no specific approvers are selected, privileged role administrators/global administrators will become the default approvers.
upvoted 1 times
...
maniaX
2 years, 9 months ago
Correct answer is Y/Y/Y: First two questions asks if the users receive notification when role was successfully activated. NOT TALKING ABOUT ACTIVATION REQUEST Third question is about notification which will be send to user who must approve role activation and since there are no approvers specified then only Privileged Role Administrator will receive notification.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...