Microsoft Certified: Identity and Access Administrator AssociateImplement an authentication and access management solutionMedium

A company uses Azure AD and has implemented Azure AD Privileged Identity Management (PIM) for its critical administrative roles. The security team wants to ensure that all activations of the 'Global Administrator' role require approval from a designated security group, and that the activation period is limited to a maximum of four hours. Which PIM setting should the administrator configure to meet these requirements?

  1. AAzure AD roles
  2. BAssignment settings
  3. CRole settings
  4. DMembers settings
Show answer & explanation

Correct answer: C. Role settings

PIM 'Role settings' (also known as 'Assignment settings' in the PIM interface) determine how a role can be activated, including requirements for approval, multi-factor authentication, justification, and the maximum activation duration. Configuring these settings for the 'Global Administrator' role will enforce the approval and time limit requirements.

Why the other options are wrong

  • A. Azure AD roles are the roles themselves, not the settings that govern their activation.
  • B. While 'Assignment settings' is sometimes used interchangeably in the UI, 'Role settings' is the overarching term for configuring the activation and assignment properties of a PIM-managed role.
  • D. Members settings relate to who is eligible for a role, not the activation parameters of the role itself.

PIM Role Settings

Configurations within Azure AD Privileged Identity Management that define requirements for activating and assigning a privileged role, such as approval, MFA, and maximum duration.

  • Governs activation requirements (approval, MFA, justification).
  • Sets maximum activation duration.
  • Configured per role in PIM.

Memory trick: Settings Govern Role Activations.

More Implement an authentication and access management solution questions