Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium
A consulting firm uses Microsoft Entra ID and has implemented PIM for Azure AD roles. They have a policy that consultants should have eligible assignments to highly privileged roles like 'User Access Administrator' for a maximum of 6 months. After this period, their eligibility should automatically expire. Which PIM setting should be configured to enforce this policy?
- AMaximum activation duration
- BRequire MFA for activation
- CPIM role settings for active assignments
- DEligible duration for assignment
Show answer & explanationAnswer & explanation
Correct answer: D. Eligible duration for assignment
The 'Eligible duration for assignment' setting in PIM role settings controls how long a user remains eligible for a role before their eligibility automatically expires. Setting this to 6 months fulfills the requirement.
Why the other options are wrong
- A. This setting defines how long a role can be active once a user activates it, not the duration of their eligibility.
- B. This setting enforces MFA during role activation, unrelated to eligibility duration.
- C. This refers to settings for permanently assigned roles, not for limiting the duration of eligible assignments.
PIM Eligible Assignment Duration
A Microsoft Entra PIM setting that specifies the maximum period a user can be eligible for a privileged role before their eligibility automatically expires, enforcing time-bound access.
- Applies to 'eligible' assignments, not 'active' assignments.
- Can be configured for a fixed period (e.g., days, months) or as permanent.
- Helps enforce Just-In-Time (JIT) access principles by limiting eligibility.
Memory trick: Eligibility has a timer, activation has its own.