Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium

A defense contractor uses Microsoft Entra ID and has mandated that all 'Security Administrator' role activations must be approved by two separate individuals: first by the user's direct manager, and then by a member of the 'Security Operations' group. Both approvals are mandatory. Which PIM setting should be configured to achieve this multi-stage approval workflow?

  1. ARequire multi-factor authentication for activation
  2. BRequire approval to activate
  3. CRequire justification on activation
  4. DMaximum activation duration
Show answer & explanation

Correct answer: B. Require approval to activate

To enable a multi-stage approval process for PIM role activations, you must configure 'Require approval to activate'. This setting allows you to define multiple approval stages, including specifying different approvers for each stage (e.g., manager, then a specific group).

Why the other options are wrong

  • A. This enforces MFA, but does not involve an approval process.
  • C. This requires a reason for activation, but does not enable an approval workflow.
  • D. This setting controls how long the role is active, not the approval process itself.

PIM Multi-Stage Approval

A feature in Microsoft Entra PIM that requires more than one approver to grant access to a privileged role, adding an extra layer of security and oversight.

  • Can include up to two stages of approval.
  • Each stage can have different approvers (e.g., manager, specific users/groups).
  • Enhances security for highly sensitive roles.

Memory trick: Two approvals mean double the check, double the security.

More Implement access governance questions