Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium

A company uses Microsoft Entra ID and has configured Privileged Identity Management (PIM) for its critical Azure resource roles. They want to ensure that if an eligible administrator's account is compromised, the attacker cannot immediately activate a privileged role. The security team needs to enforce that all role activations require an additional layer of verification beyond the usual sign-in credentials. Which PIM setting should be configured for these Azure resource roles to meet this requirement?

  1. ASet activation maximum duration
  2. BRequire justification on activation
  3. CRequire approval to activate
  4. DRequire multi-factor authentication for activation
Show answer & explanation

Correct answer: D. Require multi-factor authentication for activation

Requiring multi-factor authentication (MFA) for activation adds an additional layer of verification, making it significantly harder for an attacker with stolen credentials to activate a privileged role.

Why the other options are wrong

  • A. Setting an activation maximum duration limits the time a role is active but does not prevent an attacker from activating it in the first place.
  • B. Requiring justification adds an audit trail but does not provide an additional authentication factor to prevent unauthorized activation.
  • C. Requiring approval adds a human gate, but if the approver's account is also compromised or if the attacker can bypass approval, it's not a direct additional authentication factor for the activating user.

PIM MFA for Activation

A security setting in Privileged Identity Management that mandates multi-factor authentication (MFA) for users before they can activate an eligible privileged role.

  • Adds an extra layer of security to privileged role activation.
  • Protects against credential compromise.
  • Applicable to both Microsoft Entra roles and Azure resource roles.

Memory trick: MFA for PIM is like a second lock on the vault door.

More Implement access governance questions