Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are securing an Azure subscription named Contoso-Prod. A policy states that the built-in Owner role must be granted to the operations team only when they need it, the request must be approved by a second administrator, and the privilege must automatically expire after two hours. What should you configure to satisfy the policy while minimizing ongoing administrative effort?
Permanently assign the Owner role to the operations team at the subscription scope.
Create an eligible assignment for the Owner role to an Azure AD security group in Privileged Identity Management, require approval, and set a two-hour activation limit.
Create a Conditional Access policy that restricts Owner role sign-in sessions to two hours.
Configure an Access Review for the Owner role that runs every two hours.
Privileged Identity Management (PIM) supports eligible role assignments that users must actively activate. For an eligible assignment you can:
require approval from one or more designated approvers before activation, and
set the maximum activation duration (in this case two hours), after which the role is automatically revoked. Creating an eligible assignment for an Azure AD security group and assigning the Owner role to that group at the subscription scope meets all requirements with minimal overhead.
Access Reviews can periodically validate assignments but do not provide just-in-time activation or time-bound approvals. Conditional Access governs sign-in conditions, not RBAC role lifetimes. A permanent Owner assignment violates the policy altogether.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Privileged Identity Management (PIM)?
Open an interactive chat with Bash
What is an eligible assignment in Azure PIM?
Open an interactive chat with Bash
Why is creating an Access Review not sufficient for this scenario?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .