Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium

A consulting firm provides services to multiple clients and needs to grant their consultants temporary access to client-specific applications in Microsoft Entra ID. The firm wants to ensure that when a consultant is assigned an eligible role in PIM for a client's tenant, this assignment automatically expires after a maximum of 90 days, and the consultant must re-request eligibility if they still need it. Which PIM setting for the role should be configured?

  1. ARequire access review for eligible assignments
  2. BAssignment duration for eligible assignments
  3. CRequire multi-factor authentication on activation
  4. DMaximum activation duration
Show answer & explanation

Correct answer: B. Assignment duration for eligible assignments

The 'Assignment duration for eligible assignments' setting specifically dictates how long a user remains eligible for a PIM role before their eligibility automatically expires, which directly addresses the 90-day re-eligibility requirement.

Why the other options are wrong

  • A. Requiring access review for eligible assignments initiates a review process, but it doesn't automatically expire the eligibility after a fixed duration like 90 days.
  • C. Requiring MFA on activation secures the activation process, not the duration of eligibility.
  • D. Maximum activation duration controls how long a role is active once assigned, not the duration of eligibility.

PIM Assignment Duration for Eligible Assignments

A PIM setting that defines the maximum period a user can maintain an 'eligible' assignment for a privileged role before their eligibility automatically expires.

  • Controls the maximum duration of *eligibility*.
  • Ensures Just-In-Time (JIT) principles for *potential* access.
  • Requires re-request for eligibility after expiration.

Memory trick: Eligibility has a clock, after 90 days, it's off the block.

More Implement access governance questions