After creating a new Azure subscription, synced on-premises user accounts cannot be assigned roles in that subscription. To enable assigning Azure and Microsoft 365 roles to those synced accounts, what should you do first?
Choose an answer
Tap an option to check your answer.
Correct answer: Change the Azure AD tenant associated with the new subscription.
Why this is the answer
The correct answer is to change the Azure AD tenant associated with the new subscription. When a new Azure subscription is created, it defaults to a new Azure AD tenant. To manage resources in this subscription with existing synced on-premises user accounts, the subscription must be associated with the Azure AD tenant that contains those synced accounts. This allows the existing identities to be recognized and assigned roles within the new subscription. Configuring pass-through or federated authentication relates to how users authenticate, not which Azure AD tenant a subscription is linked to. These options would not resolve the issue of user accounts not being recognized for role assignments. Installing a second instance of Azure AD Connect is unnecessary and could lead to synchronization conflicts; the existing Azure AD Connect instance already synchronizes accounts to the primary Azure AD tenant.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed