Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium

A manufacturing company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. The security team wants to ensure that when an administrator activates a PIM role, they must provide a business justification, and this justification must be reviewed and approved by another designated administrator before the role is actually activated. Which PIM setting should be configured to enforce this requirement?

  1. ARequire multi-factor authentication on activation
  2. BRequire justification on activation
  3. CMaximum activation duration
  4. DRequire approval to activate
Show answer & explanation

Correct answer: D. Require approval to activate

The 'Require approval to activate' setting in PIM ensures that a designated approver must review and approve the activation request, which includes the provided justification, before the role becomes active.

Why the other options are wrong

  • A. Requiring MFA on activation adds a security layer for the activating user but doesn't involve another administrator's approval.
  • B. Requiring justification on activation makes the user provide a reason but does not enforce another administrator to review or approve it.
  • C. Maximum activation duration controls how long a role can be active, not the approval process.

PIM 'Require approval to activate'

A PIM setting that mandates an explicit approval from a designated approver(s) for a user's role activation request to proceed.

  • Enhances security for privileged role activations.
  • Requires a specified approver or group.
  • Justification is typically part of the approval review.

Memory trick: Activation needs a 'go', not just a 'why' or a 'how long' to flow.

More Implement access governance questions