Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium

A consulting firm uses Microsoft Entra ID and has implemented PIM for Azure AD roles. They have a policy that consultants should have eligible assignments to highly privileged roles like 'User Access Administrator' for a maximum of 6 months. After this period, their eligibility should automatically expire. Which PIM setting should be configured to enforce this policy?

  1. AMaximum activation duration
  2. BRequire MFA for activation
  3. CPIM role settings for active assignments
  4. DEligible duration for assignment
Show answer & explanation

Correct answer: D. Eligible duration for assignment

The 'Eligible duration for assignment' setting in PIM role settings controls how long a user remains eligible for a role before their eligibility automatically expires. Setting this to 6 months fulfills the requirement.

Why the other options are wrong

  • A. This setting defines how long a role can be active once a user activates it, not the duration of their eligibility.
  • B. This setting enforces MFA during role activation, unrelated to eligibility duration.
  • C. This refers to settings for permanently assigned roles, not for limiting the duration of eligible assignments.

PIM Eligible Assignment Duration

A Microsoft Entra PIM setting that specifies the maximum period a user can be eligible for a privileged role before their eligibility automatically expires, enforcing time-bound access.

  • Applies to 'eligible' assignments, not 'active' assignments.
  • Can be configured for a fixed period (e.g., days, months) or as permanent.
  • Helps enforce Just-In-Time (JIT) access principles by limiting eligibility.

Memory trick: Eligibility has a timer, activation has its own.

More Implement access governance questions