Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium
A manufacturing company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. The security team wants to ensure that when an administrator activates a PIM role, they must provide a business justification, and this justification must be reviewed and approved by another designated administrator before the role is actually activated. Which PIM setting should be configured to enforce this requirement?
- ARequire multi-factor authentication on activation
- BRequire justification on activation
- CMaximum activation duration
- DRequire approval to activate
Show answer & explanationAnswer & explanation
Correct answer: D. Require approval to activate
The 'Require approval to activate' setting in PIM ensures that a designated approver must review and approve the activation request, which includes the provided justification, before the role becomes active.
Why the other options are wrong
- A. Requiring MFA on activation adds a security layer for the activating user but doesn't involve another administrator's approval.
- B. Requiring justification on activation makes the user provide a reason but does not enforce another administrator to review or approve it.
- C. Maximum activation duration controls how long a role can be active, not the approval process.
PIM 'Require approval to activate'
A PIM setting that mandates an explicit approval from a designated approver(s) for a user's role activation request to proceed.
- Enhances security for privileged role activations.
- Requires a specified approver or group.
- Justification is typically part of the approval review.
Memory trick: Activation needs a 'go', not just a 'why' or a 'how long' to flow.