Cloud · Microsoft Azure · Certifications
AZ-500: Least-privilege role for synchronization options
Select one answer. Your result and the explanation will appear immediately.
Question 5
Your organization's network includes an on-premises Active Directory domain named adatum.com that synchronizes with Azure Active Directory using Azure AD Connect. The Azure AD Connect tool is installed on Server1. To adhere to the principle of least privilege, you need to assign an Azure AD role to a domain administrator from adatum.com that allows them to modify synchronization options. Which Azure AD role should you assign?
Correct answer: Hybrid Identity Administrator
The Hybrid Identity Administrator role is designed for managing Microsoft Entra hybrid identity features, including Azure AD Connect synchronization settings. It provides the required hybrid identity permissions without assigning the broader Global Administrator role.
Exam clue: “Azure AD Connect”, “modify synchronization options”, and “least privilege” point to Hybrid Identity Administrator.
Remember: Use Hybrid Identity Administrator for hybrid identity and synchronization administration. Reserve Global Administrator for tasks that truly require tenant-wide control.