Microsoft Azure Security Technologies (AZ-500)

Disable ads (and more) with a membership for a one time $4.99 payment

Study for the Microsoft Azure Security Technologies (AZ-500) exam. Prepare with well-structured questions and detailed explanations. Enhance your understanding and improve your readiness for the certification exam!

Practice this question and more.


Which user role is necessary for a domain admin to manage Azure AD Connect settings for on-premises synchronization options?

  1. Global administrator

  2. Security administrator

  3. Privileged Role Administrator

  4. Billing administrator

The correct answer is: Global administrator

The correct choice is the Global administrator role. This role is essential for managing Azure Active Directory (Azure AD) and specifically for configuring settings related to Azure AD Connect, which is the tool used to synchronize on-premises directories with Azure AD. The Global administrator has the highest level of permissions in Azure AD and can manage all aspects of Azure AD and its resources, including setting up and maintaining Azure AD Connect. This includes creating and managing users, groups, and roles, and granting other users roles and permissions as necessary. In the context of Azure AD Connect, configuring synchronization options typically involves managing user accounts, directory services, and authentication methods which are privileges exclusively granted to Global administrators. Additionally, this role provides the flexibility needed to address various configuration changes that may involve multiple aspects of Azure AD and on-premises directory settings. The other roles mentioned, such as Security administrator, Privileged Role Administrator, and Billing administrator, do not inherently possess the full array of permissions necessary for managing Azure AD Connect settings. While they can manage specific areas within Azure AD, they do not have the comprehensive access required to modify all syncing configurations effectively, which is why the Global administrator is the necessary role for this task.