Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium
A global administrator has enabled Azure AD Privileged Identity Management (PIM) in their Microsoft 365 tenant. They want to ensure that users assigned to the 'Global Administrator' role must always justify their elevated access and have it automatically revoked after a maximum of 4 hours. Which PIM setting should be configured for the Global Administrator role?
- ANotification settings for role activation
- BPermanent assignment with expiry
- CActivation maximum duration and justification requirement
- DMulti-Factor Authentication (MFA) enforcement for activation
Show answer & explanationAnswer & explanation
Correct answer: C. Activation maximum duration and justification requirement
To meet the requirements of justifying elevated access and automatic revocation after 4 hours, the administrator must configure the 'Activation maximum duration' to 4 hours and enable the 'Require justification on activation' setting within the PIM role settings.
Why the other options are wrong
- A. Notification settings inform about activation, but do not control the justification or duration of access.
- B. Permanent assignment with expiry is for time-bound assignments, not for just-in-time (JIT) activation with a short maximum duration.
- D. MFA enforcement is a security measure for activation, but doesn't address justification or the automatic revocation duration.
PIM Role Settings
Configurable parameters within Azure AD Privileged Identity Management that define how eligible users can activate and use privileged roles.
- Control activation duration.
- Enforce justification for activation.
- Require MFA for activation.
- Set up approval workflows.
Memory trick: PIM settings are your access control panel: how long, why, and how secure.