AZ-303 Exam QuestionsBrowse all questions from this exam

AZ-303 Exam - Question 244


Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Active Directory (Azure AD) tenant named contoso.com.

A user named Admin1 attempts to create an access review from the Azure Active Directory admin center and discovers that the Access reviews settings are unavailable. Admin1 discovers that all the other Identity Governance settings are available.

Admin1 is assigned the User administrator, Compliance administrator, and Security administrator roles.

You need to ensure that the Admin1 can create access reviews in contoso.com.

Solution: You consent to Azure AD Privileged Identity Management (PIM).

Does this meet the goal?

Show Answer
Correct Answer: B

The solution to ensure that Admin1 can create access reviews in contoso.com is to assign them the appropriate license and role required for access reviews. While Azure AD Privileged Identity Management (PIM) is a useful tool for managing permissions and roles, simply consenting to PIM does not address the specific issue of access review settings being unavailable. The prerequisites for creating access reviews include having an Azure AD Premium P2 license and being a Global administrator or User administrator. Since Admin1 is already a User administrator, the absence of the correct licensing is likely the core issue. Therefore, consenting to PIM alone does not meet the goal.

Discussion

17 comments
Sign in to comment
[Removed]Option: B
Mar 4, 2021

NO https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review Prerequisites: Azure AD Premium P2 Global administrator or User administrator (Admin is User administrator)

KravieccOption: B
Jan 16, 2021

No is the correct answer. It looks like the tenant has not been onboarded yet.

J4UOption: A
Sep 4, 2021

Correct: YES (All other options like Global Admin, P2 license etc are No as Admin1 is already a User Admin) Identity governance scope the access review to Teams + M365 Groups and Applications whereas PIM scope the access review for Users and Groups + Service Principal. So PIM is suitable place for access reviews. The pre-reqs are access review creator should be either User or Global Admin and they no need to have P2 license. However the reviewer should have P2 license to review it.

DNeoOption: A
Mar 20, 2021

Question doesn't mention about having Azure AD P2 license. Assuming it has already been there (Per user participating in Access Review), PIM should work here

AzureGCOption: A
Apr 26, 2021

Y : PIM, See the note, here: https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/subscription-requirements Azure AD Premium P2 licenses are not required for the following tasks: No licenses are required for users who set up PIM, configure policies, receive alerts, and set up access reviews.

KrstoOption: B
Feb 13, 2021

Tenant does not have a valid license (EMS E5 or P2) required for Access reviews. You get this message when trying to see Access Reviews. And this is with Global admin role. In order to use this you need to have: Azure AD Premium P2 Global administrator or User administrator https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review

nicksuOption: B
Jul 13, 2021

This seem to be an outdated question. There is no need to consent to PIM anymore

tita_tovenaarOption: B
Jul 25, 2021

Y - as commented earlier, P2 license is not needed to *create* access reviews. You need P2 to execute them. To use a metaphore, it's free and easy to sign up for a phone, but actual use costs money :-)

legendkiller84Option: B
Feb 25, 2021

PIM also needs an Azure AD P2 license: https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/subscription-requirements

Mj11AzOption: A
May 21, 2021

If an Azure AD Premium P2, EMS E5, or trial license expires, Privileged Identity Management features will no longer be available in your directory: But here they can able to consent the PIM i.e P2 license is available. Answer should be yes.

samsanta2012Option: B
May 21, 2021

NO. Prerequisite to create access reviews in PIM Azure AD Premium P2 license Owner or User Access Administrator Azure role for the resource https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-resource-roles-start-access-review#prerequisite-license

jr_lucianoOption: A
Jan 12, 2022

Correct Answer: A (YES) The problem here is not license.

marmadukeOption: B
Feb 6, 2022

Azure AD Premium P2 licenses are NOT required for the following tasks: No licenses are required for users who set up PIM, configure policies, receive alerts, and SET UP ACCESS REVIEWS. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/subscription-requirements

OLO_90Option: B
Jan 22, 2021

No, you need to purchase an Azure Directory Premium P2 license for contoso.com.

Aghora
Jan 28, 2021

no you dont , try and test it . you need Global Administrator or Privileged Role Administrator to do this , I tested without P2

syu31svcOption: A
Aug 29, 2021

https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-resource-roles-start-access-review https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-start-security-review Answer is Yes

tteesstt
Aug 30, 2021

Both of your links clearly state the following: "Using this feature requires an Azure AD Premium P2 license." I have Owner and Global Administrator role but Access Review still asks me for license.

AD3Option: A
Feb 12, 2022

Correction to my comment. The answer is YES.

RissanOption: B
Mar 18, 2022

The question is not about license assumption is P2 license is already there. P2 license is a pre-requiste for PIM