Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium

A global consulting firm uses Microsoft Entra ID and has implemented a strict policy for privileged access. All global administrators must have their assignments in Privileged Identity Management (PIM) configured as 'eligible' rather than 'active'. The security team wants to ensure that these administrators periodically reconfirm their need for eligibility to this role, even if they don't activate it frequently. Which PIM setting for the Azure AD Global Administrator role should the security team configure to meet this requirement?

  1. AMaximum activation duration
  2. BRequire multi-factor authentication on activation
  3. CRequire access review for eligible assignments
  4. DRequire justification on activation
Show answer & explanation

Correct answer: C. Require access review for eligible assignments

The 'Require access review for eligible assignments' setting in PIM specifically targets eligible assignments, ensuring that users with standing eligibility must periodically review and justify their continued need for that eligibility, regardless of activation frequency.

Why the other options are wrong

  • A. Maximum activation duration controls how long a role can be active once activated, not the review of eligibility.
  • B. Requiring MFA on activation secures the activation process, not the periodic review of eligibility.
  • D. Requiring justification on activation ensures a reason is provided when activating, not a periodic review of eligibility.

PIM Access Review for Eligible Assignments

A PIM setting that configures a recurring review process for users who have standing eligibility for a privileged role, ensuring their continued need for that eligibility is validated.

  • Targets 'eligible' assignments, not 'active' ones.
  • Ensures periodic re-validation of potential access.
  • Important for maintaining least privilege principle.

Memory trick: Eligible means 'can be', but still needs a review to see.

More Implement access governance questions