Microsoft Certified: Azure Administrator AssociateManage Azure identities and governanceMedium

A company uses Azure Active Directory (Azure AD) to manage its user accounts. They have a global directory with thousands of users. Due to a recent organizational change, several user accounts need to have their 'Department' attribute updated to a new value. This change affects approximately 500 users. What is the most efficient method to perform this bulk update?

  1. AUtilize Azure AD Identity Protection to update user attributes.
  2. BImplement Azure AD Conditional Access policies to modify user attributes.
  3. CUse PowerShell with the Azure AD module to script the updates.
  4. DManually update each user's profile in the Azure portal.
Show answer & explanation

Correct answer: C. Use PowerShell with the Azure AD module to script the updates.

For bulk updates affecting a significant number of users (e.g., 500), scripting with PowerShell and the Azure AD module is significantly more efficient and less error-prone than manual updates. It allows for automated processing based on a list of users.

Why the other options are wrong

  • A. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not on bulk attribute updates.
  • B. Conditional Access policies enforce access controls based on attributes but do not modify user attributes themselves.
  • D. Manually updating 500 users is highly inefficient and prone to errors.

Azure AD Bulk User Attribute Update (PowerShell)

Using PowerShell cmdlets from the Azure AD module to programmatically modify attributes for multiple user accounts in Azure Active Directory.

  • Efficient for large numbers of users.
  • Reduces manual effort and potential for errors.
  • Requires Azure AD PowerShell module and appropriate permissions.

Memory trick: For many users, PowerShell is the bulk update wizard.

More Manage Azure identities and governance questions