Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You have onboarded a resource group named RG1 to Microsoft Entra Privileged Identity Management (PIM). A security policy states that any user who activates the Contributor role for RG1 must first perform multifactor authentication (MFA). Currently, eligible users can activate the role without MFA. You must enforce the policy while keeping users in an eligible state and without creating additional Conditional Access rules. What should you do?

  • Configure an access review for the Contributor role in RG1 and set Enforce MFA as an evaluation condition.

  • Create a new time-bound Active assignment of the Contributor role for each user and select Require MFA during assignment.

  • Edit the Contributor role settings for RG1 in PIM and enable the Require multifactor authentication on activation option.

  • Modify the global PIM security settings and enable multifactor authentication requirement for all privileged role activations.

Microsoft Azure Security Engineer Associate AZ-500
Secure identity and access
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot