AZ-303 Exam QuestionsBrowse all questions from this exam

AZ-303 Exam - Question 246


Note: This question is part of series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure Active Directory (Azure AD) tenant named contoso.com.

A user named Admin1 attempts to create an access review from the Azure Active Directory admin center and discovers that the Access reviews settings are unavailable. Admin1 discovers that all the other Identity Governance settings are available.

Admin1 is assigned the User administrator, Compliance administrator, and Security administrator roles.

You need to ensure that the Admin1 can create access reviews in contoso.com.

Solution: You purchase an Azure Directory Premium P2 license for contoso.com.

Does this meet the goal?

Show Answer
Correct Answer: A

To create access reviews in Azure Active Directory (Azure AD), an Azure AD Premium P2 license is required for the tenant. Admin1, who is assigned the User administrator, Compliance administrator, and Security administrator roles, will need this type of license for the Access reviews settings to be available. This licensing requirement is necessary for enabling features under Identity Governance, including access reviews, which are part of the Azure AD Premium P2 offering.

Discussion

27 comments
Sign in to comment
nemojzapipu
Jan 7, 2021

YES It clearly states that user wants to access section "Access review" from AAD (Identity Governance) which leads to: A valid Azure AD Premium P2, Enterprise Mobility + Security E5 paid, or trial license is required to use Azure AD access reviews. I tried this on two tenants. 1. Global Admin + P2 -> I can create Access review -> https://ibb.co/8j81w5p 2. Global Admin without P2 -> Cannot access "Access review" -> https://ibb.co/QFC2hh6

xaccan
Jan 10, 2021

Answer is No, PIM is required. read more here: https://www.examtopics.com/discussions/microsoft/view/8821-exam-az-300-topic-16-question-6-discussion/

crazyaboutazure
Jul 10, 2021

what about tenant not onboarded yet requirement?

J4U
Sep 4, 2021

I tested it as a User Admin w/o P2 license and I am able to create access review from IG. So the requirement is the reviewers should have P2 license, not the creators.

BigR
Mar 10, 2021

Ans is Yes Admin1 has AD Premium P2 license + User administrator.

malyaban
Mar 16, 2021

Yes I think according to https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review both these are required, they are not either/or, so other 2 questions must be NO as PIM does not help here and giving Global Admin without the license also will fail

Alivina
May 10, 2021

I think the answer is NO. https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview Azure AD Premium P2 licenses are not required for users with the Global Administrator or User Administrator roles who set up (CREATE) access reviews, configure settings, or apply the decisions from the reviews. For example, An administrator creates an access review of Group B with 500 users and 3 group owners, and assigns the 3 group owners as reviewers. Only required 3 Licenses.

UnknownSecret
Jul 19, 2021

Hmmm.... When I read the lik, the one YOU provided, I see the below sentence: Using this feature requires an Azure AD Premium P2 license. On what basis you claim that "Azure AD Premium P2 licenses are not required...."

Mj11Az
May 21, 2021

Yes, Azure AD Premium P2 Global administrator or User administrator

nfett
Jun 22, 2021

repeat

syu31svc
Aug 28, 2021

User Administrator role does not require P2 license to setup access reviews. Instead, you need to onboard access reviews in your tenant. https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview Answer is No

firstabed
Feb 18, 2021

Ensure that your directory has at least as many Azure AD Premium P2 licenses as you have employees that will be performing the following tasks Azure AD Premium P2 licenses are not required for the following tasks: No licenses are required for users who set up PIM, configure policies, receive alerts, and set up access reviews. So , Ans NO

StarkStrange
Feb 24, 2021

Ans is Yes. for access review.. Global Admin/user admin role is needed which Admin1 has another requirement is P2 license so ans is yes here. https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review

StarkStrange
Feb 24, 2021

Ans is No, as admin is trying to use Active Directory Admin center.. where as PIM could be used with User Admin role.

[Removed]
Mar 4, 2021

YES: https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review Prerequisites Azure AD Premium P2 Global administrator or User administrator

malyaban
Mar 16, 2021

Also, for all such confusion in the solution notes -- https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure shows clearly that -- Using PIM feature requires an Azure AD Premium P2 license !!

Anonymous
Apr 30, 2021

Prerequisite license - Azure AD Premium P2 license. Azure Portal --> Identity Governance --> Privileged Identity Management --> Azure resources --> access review So, with P2 license, it is not auto, still need PIM.

Ario
Aug 28, 2021

Prerequisites for Access review : Azure AD Premium P2 Global administrator or User administrator Microsoft 365 and Security group owner (Preview)

AD3
Feb 13, 2022

Look at the page and expand Identity Governance. You will see bunch of items under it and the statement in the problem says all other identity governance are available. That means the P2 license is enabled. Only thing that is needed is to use PIM. So answer is NO. https://www.microsoft.com/en-us/security/business/identity-access-management/azure-ad-pricing?rtc=1

sukhdeep
Jan 15, 2021

I did tested without P2 license you can't do access review.

bbartek
Jan 17, 2021

"Admin1 discovers that all the other Identity Governance settings are available." - this sentence implies, that P2 is already in place, since P2 is required for Identity Governance

gizda2
Oct 6, 2021

The truth is here with bbartek.

gizda2
Oct 6, 2021

The truth is here with bbartek.

G_Z
Jan 18, 2021

Azure AD Premium P2 license. and PIM configuration

mindtrax
Feb 4, 2021

Just purchasing Azure Directory Premium P2 license won't cut it, the user still needs to have the correct role.

Stephan99
Feb 6, 2021

Azure AD Premium P2 licenses are not required for users with the Global Administrator or User Administrator roles who set up access reviews, configure settings, or apply the decisions from the reviews. https://docs.microsoft.com/en-us/azure/active-directory/governance/access-reviews-overview

Krsto
Feb 13, 2021

With P2 license and User admin role you should have access. Tenant does not have a valid license (EMS E5 or P2) required for Access reviews. You get this message when trying to see Access Reviews. And this is with Global admin role. In order to use this you need to have: Azure AD Premium P2 Global administrator or User administrator https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review

aabdous
Apr 12, 2021

Answer is YES https://docs.microsoft.com/en-us/azure/active-directory/governance/deploy-access-reviews#licenses

rockyykrish
May 2, 2021

if you have a P2 License you can get an access review. So the answer should be yes.

Hrithiktej
Jul 1, 2021

seems correct to me under what does it do ? section of this What is Azure AD Privileged Identity Management? we see "Conduct access reviews to ensure users still need roles" https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure

network_zeal
Aug 16, 2021

YES, need p2 license to create access review

aabdous
Aug 16, 2021

Answer is Yes. Look this page https://docs.microsoft.com/en-us/azure/active-directory/governance/create-access-review Show Prerequisites

bigticket
Dec 29, 2021

YES. You need a valid Azure AD Premium (P2) license for each person, other than Global administrators or User administrators, who will create or do access reviews. https://docs.microsoft.com/en-us/azure/active-directory/governance/deploy-access-reviews

SKAZ303
Jan 2, 2022

Sould be A. Premium P2 ($9 per user per month) Everything offered in P1 Identity Protection Privileged Identity Management Access reviews

jr_luciano
Jan 12, 2022

Correct Answer: B (NO)

BhupalS
Jan 23, 2022

Azure AD Premium P2 licenses are not required for the following tasks: No licenses are required for users who set up PIM, configure policies, receive alerts, and set up access reviews. https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/subscription-requirements