Microsoft 365 Certified: Administrator ExpertDeploy and manage a Microsoft 365 tenantMedium
A global administrator has enabled Azure AD Privileged Identity Management (PIM) for their Microsoft 365 tenant. They want to ensure that all users assigned to the 'Global Administrator' role must provide a justification and multi-factor authentication (MFA) when activating the role. Additionally, the activation period for this role should be limited to a maximum of four hours. Which PIM role setting should the administrator configure to meet these requirements?
- AActivation maximum duration
- BRequire multi-factor authentication on activation
- CAll of the above
- DRequire justification on activation
Show answer & explanationAnswer & explanation
Correct answer: C. All of the above
To meet all specified requirements, the administrator must configure multiple PIM role settings. Specifically, they need to set the 'Activation maximum duration' to four hours, enable 'Require multi-factor authentication on activation', and enable 'Require justification on activation' for the Global Administrator role.
Why the other options are wrong
- A. This only addresses the duration requirement, not MFA or justification.
- B. This only addresses the MFA requirement, not duration or justification.
- D. This only addresses the justification requirement, not duration or MFA.
Azure AD PIM Role Settings
Azure AD Privileged Identity Management (PIM) allows administrators to manage, control, and monitor access to important resources. PIM role settings define the rules for how eligible users activate their roles, including requirements for MFA, justification, approval, and maximum activation duration.
- Configurable per role in Azure AD PIM.
- Includes settings for activation duration (e.g., 4 hours).
- Allows requiring MFA for role activation.
- Enables requiring justification for role activation.
- Supports requiring approval for role activation.
Memory trick: PIM settings: Time, MFA, and a reason, secure access for every season.