AKS Azure AD authentication can only be enabled at cluster creation, so you must recreate the cluster to enable Microsoft Entra account access

Plan and implement advanced security for compute
Answer Correct answer: A — Recreate AKS1 with Microsoft Entra ID authentication enabled at creation, since AKS Entra integration cannot be added to an existing cluster.

You have a Microsoft Entra tenant named Contoso.com and an Azure Kubernetes Service (AKS) cluster AKS1. You discover that AKS1 cannot be accessed by using accounts from Contoso.com. You need to ensure AKS1 can be accessed by using accounts from Contoso.com. The solution must minimize administrative effort. What should you do first?

  1. From Azure, recreate AKS1. Correct Answer
  2. From AKS1, upgrade the version of Kubernetes.
  3. From Microsoft Entra, add a Microsoft Entra ID P2 license.
  4. From Microsoft Entra, configure the User settings.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The constraint is creation-time only: you cannot retrofit legacy Azure AD integration onto an already-running AKS cluster. 'Recreate' is the minimal viable path when access via Entra accounts is required and was not set at creation.

AKS Azure AD (Microsoft Entra ID) integration is bound to the cluster at creation time. If an existing cluster was not created with Entra integration, accounts from the Entra tenant cannot authenticate to it; the only way to enable that access is to recreate the cluster with Entra ID authentication configured during creation.

Candidates pick 'configure User settings' or 'add a P2 license', but those do not enable AKS to trust Entra accounts; the cluster itself must be created with Entra ID integration, which requires recreation.

Community Discussion (3 comments)

Abdullah14 👍 3 Selected: A
account accesses happens in the phase of creation of the kubernetes service
chiquito 👍 2
Answer A: is correct This was already sorted out under : Question #42Topic 3 The following limitations apply: Azure AD can only be enabled on Kubernetes RBAC-enabled cluster. Azure AD legacy integration can only be enabled during cluster creation. Reference: https://docs.microsoft.com/en-us/azure/aks/azure-ad-integration-cli
mrt007 👍 2
Given the options, the best first step would be: D. From Microsoft Entra, configure the User settings. This would involve setting up the necessary permissions for Contoso.com accounts to access the AKS1 cluster. This is a more direct solution compared to the other options and requires less administrative effort. Recreating the AKS cluster or upgrading Kubernetes wouldn’t necessarily resolve an access issue, and adding a Microsoft Entra ID P2 license is not directly related to access management.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure AD / Microsoft Entra ID integration for AKS is configured when the cluster is created and, on the legacy integration path, cannot be enabled afterward. Because AKS1 was created without it and now must accept Contoso.com accounts, the first step is to recreate AKS1 with Microsoft Entra ID authentication enabled at creation. (Option A)

Why the Other Options Are Wrong

  • Option B (Upgrade Kubernetes version) does not add Entra ID authentication capability.
  • Option C (Add Entra ID P2 license) is unrelated to AKS cluster authentication binding.
  • Option D (Configure User settings) changes directory-level user consent, not the cluster's Entra trust.

Community Comment Notes

A comment referenced the AKS Azure AD integration CLI doc and the limitation: 'Azure AD legacy integration can only be enabled during cluster creation,' so recreation (A) is required.

Official Reference

Related Analysis

← Back to AZ-500 Study Guide