Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium
A software development company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure resources. They have a policy that developers should only be able to activate certain highly sensitive roles, such as 'User Access Administrator' for a maximum of 4 hours at a time. After this period, the role should automatically deactivate. Which PIM setting should be configured for these roles?
- AMaximum activation duration
- BRequire approval to activate
- CRequire justification on activation
- DAssignment duration for eligible assignments
Show answer & explanationAnswer & explanation
Correct answer: A. Maximum activation duration
The 'Maximum activation duration' setting in PIM directly controls how long an activated role remains active before it is automatically deprovisioned, which aligns with the requirement for a 4-hour limit.
Why the other options are wrong
- B. Requiring approval adds a step for another admin to approve activation but doesn't control the duration.
- C. Requiring justification adds a reason for activation but doesn't control the duration.
- D. Assignment duration for eligible assignments controls how long a user is *eligible* for a role, not the maximum period the role can be *active* once activated.
PIM Maximum Activation Duration
A PIM setting that specifies the longest period a privileged role can remain active after a user has activated it, promoting Just-In-Time (JIT) access.
- Limits time-bound access to privileged roles.
- Automatically deactivates the role after the set duration.
- Enhances security by minimizing exposure time of privileged accounts.
Memory trick: Activation has a timer, don't let it run any higher.