Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceHard
A consulting firm uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. They have a critical 'Global Administrator' role that requires a multi-stage approval process before activation. The first stage of approval must be by a Security Administrator, and the second stage must be by a designated senior manager. How would you configure this multi-stage approval in PIM?
- ASet 'Require approval to activate' to Yes, then add both Security Administrator and senior manager as approvers in a single stage.
- BSet 'Require approval to activate' to Yes, then configure two distinct approval stages, assigning Security Administrator to stage 1 and the senior manager to stage 2.
- CSet 'Require approval to activate' to Yes, and configure a custom Azure Logic App to handle sequential approvals.
- DEnable 'Require justification on activation' and ensure both Security Administrator and senior manager are notified of activation requests.
Show answer & explanationAnswer & explanation
Correct answer: B. Set 'Require approval to activate' to Yes, then configure two distinct approval stages, assigning Security Administrator to stage 1 and the senior manager to stage 2.
PIM multi-stage approval directly supports configuring multiple distinct stages, where each stage has its own set of approvers. To meet the requirement, you would configure two stages, with the Security Administrator in stage 1 and the senior manager in stage 2.
Why the other options are wrong
- A. Adding both to a single stage would mean either person could approve, not a sequential multi-stage process.
- C. While Logic Apps can automate workflows, PIM's built-in multi-stage approval is the native and simpler solution for this specific requirement.
- D. This only requires justification and sends notifications, it does not enforce a multi-stage approval workflow.
PIM Multi-Stage Approval
PIM multi-stage approval allows defining multiple sequential approval stages for privileged role activation, with different approvers for each stage.
- Enhances security for highly sensitive roles.
- Each stage must be approved before proceeding to the next.
- Configured within PIM role settings.
Memory trick: Layers of security approval for critical roles.