Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium

A software development company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure resources. They have a policy that developers should only be able to activate certain highly sensitive roles, such as 'User Access Administrator' for a maximum of 4 hours at a time. After this period, the role should automatically deactivate. Which PIM setting should be configured for these roles?

  1. AMaximum activation duration
  2. BRequire approval to activate
  3. CRequire justification on activation
  4. DAssignment duration for eligible assignments
Show answer & explanation

Correct answer: A. Maximum activation duration

The 'Maximum activation duration' setting in PIM directly controls how long an activated role remains active before it is automatically deprovisioned, which aligns with the requirement for a 4-hour limit.

Why the other options are wrong

  • B. Requiring approval adds a step for another admin to approve activation but doesn't control the duration.
  • C. Requiring justification adds a reason for activation but doesn't control the duration.
  • D. Assignment duration for eligible assignments controls how long a user is *eligible* for a role, not the maximum period the role can be *active* once activated.

PIM Maximum Activation Duration

A PIM setting that specifies the longest period a privileged role can remain active after a user has activated it, promoting Just-In-Time (JIT) access.

  • Limits time-bound access to privileged roles.
  • Automatically deactivates the role after the set duration.
  • Enhances security by minimizing exposure time of privileged accounts.

Memory trick: Activation has a timer, don't let it run any higher.

More Implement access governance questions