Your company recently created an Azure subscription.
You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM).
Which of the following is the role you should assign to the user?
A. The Global administrator role.
B. The Security administrator role.
C. The Password administrator role.
D. The Compliance administrator role.
You have been tasked with making sure that a specified user is able to implement Azure AD Privileged Identity Management (PIM).
Which of the following is the role you should assign to the user?
A. The Global administrator role.
B. The Security administrator role.
C. The Password administrator role.
D. The Compliance administrator role.
Answer: A
✅ Explanation:
-To enable and configure Azure AD Privileged Identity Management (PIM), a user must have elevated privileges because PIM controls role-based access to sensitive roles in Azure AD and Azure.
✅ Why Global Administrator is required:
Only users assigned the Global Administrator role (or Privileged Role Administrator) can enable PIM for Azure AD.
-The initial configuration of PIM (such as enabling the service, assigning roles, and managing role settings) requires Global Admin privileges.
-After PIM is enabled, other users with roles like Privileged Role Administrator can help manage it, but setup must be done by a Global Admin.
✅ Explanation:
-To enable and configure Azure AD Privileged Identity Management (PIM), a user must have elevated privileges because PIM controls role-based access to sensitive roles in Azure AD and Azure.
✅ Why Global Administrator is required:
Only users assigned the Global Administrator role (or Privileged Role Administrator) can enable PIM for Azure AD.
-The initial configuration of PIM (such as enabling the service, assigning roles, and managing role settings) requires Global Admin privileges.
-After PIM is enabled, other users with roles like Privileged Role Administrator can help manage it, but setup must be done by a Global Admin.