AZ-500 Exam QuestionsBrowse all questions from this exam

AZ-500 Exam - Question 146


You have an Azure subscription that uses Azure AD Privileged Identity Management (PIM).

A user named User1 is eligible for the Billing administrator role.

You need to ensure that the role can only be used for a maximum of two hours.

What should you do?

Show Answer
Correct Answer: BD

To ensure that a role can only be used for a maximum of two hours, you need to edit the role activation settings. This involves configuring the maximum duration that the role can be active once it is activated by the user. Editing the role assignment settings or creating an access review would not be directly related to limiting the duration of the role's usage once it is activated. Hence, the correct action is to modify the role activation settings to set the maximum activation duration to two hours.

Discussion

15 comments
Sign in to comment
xcapellOption: D
Jun 18, 2023

D. Role activation settings https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-change-default-settings

Anarchira
Jun 20, 2023

Correct

ErikPJordanOption: D
Sep 20, 2023

Double DD

OrangeSGOption: D
Oct 11, 2023

To ensure that the Billing administrator role can only be used for a maximum of two hours, you need to edit the role activation settings. To do this, follow these steps: 1. Sign in to the Azure portal. 2. Go to Azure Active Directory > Privileged Identity Management. 3. Click Roles > Role settings. 4. Select the Billing administrator role. 5. Under Activation maximum duration, set the maximum duration to 2 hours. 6. Click Save. Once you have edited the role activation settings, User1 will be able to activate the Billing administrator role for a maximum of two hours at a time. After two hours, the role assignment will automatically expire. Reference Configure Microsoft Entra role settings in Privileged Identity Management https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-change-default-settings

flafernanOption: D
Nov 9, 2023

Considering the original judgment presented in the question, letter D (Edit function activation settings) would be the most pertinent choice, since the other options would not directly apply to the function's time limitation. However, it is important to note that the actual configuration of time limitations for privileged roles must be performed through Azure AD Privileged Identity Management (PIM) policies to ensure secure use and required compliance of privileged roles. Therefore, although D may be the most detailed option based on the logic of the question, the specific configuration of the time limitation must be performed in PIM.

AjayD123Option: D
Jun 25, 2023

Role Activation settings https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-change-default-settings#role-settings

Ivan80
Jan 30, 2024

In exam 1/28/24

AlexbzOption: B
Jun 17, 2023

Answer is correct!

HaraOption: D
Jun 23, 2023

D. - Similar as xcapell https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-change-default-settingshttps://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-change-default-settings

sigvastOption: D
Jul 3, 2023

The user is eligible for the role, this means that he will request the role (it's an activation process). Assignment is when an admin manually assign a role to someone.

03038b8Option: D
Jun 26, 2023

Tested. you can Edit either from Role->Choose the role (Billing Administrator in this case)->Role Settings->Edit and then under Activation you setup Activation maximum duration or if you want Azure AD Privileged Identity Management -> Azure AD Roles -> Roles Under Manage you choose Assignments (if the role has already been assigned at least once) you click Settings-> Edit and then under Activation you setup Activation maximum duration if the role has not been assigned to someone under Manage you click Settings, you choose the role and then Edit under Activation you setup Activation maximum duration

ArioOption: D
Jul 4, 2023

D. Edit the role activation settings.

ESAJRROption: B
Aug 3, 2023

B. Edit the role assignment settings.

heatfan900Option: D
Aug 28, 2023

THE ACTIVATION TAB WITHIN THE PIM ROLE SETTINGS. ASSIGNMENT SPECIFIES WHEN THE ROLE ITSELF EXPIRES AND WHO IS ASSIGNED TO IT.

bob_sezOption: B
Nov 24, 2023

So stupid these questions. You have to indeed actually edit the Role>Assignment>Settings. But once there the duration changes are under Activation>Settings I have no idea which one MS wants selected here.

Nava702
Mar 25, 2024

So often such questions have more than one answer. Look out for those. If you select only one you will lose points.

PillartechOption: D
Jul 16, 2024

D is the answer