Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy

A manufacturing company uses Microsoft Entra ID and has implemented PIM for Azure AD roles. They want to ensure that if a user activates a highly privileged role, they are automatically de-assigned from that role after a maximum of 4 hours, regardless of whether they explicitly deactivate it. Which PIM setting should be configured to enforce this strict time limit for active role assignments?

  1. APIM role settings for permanent assignments
  2. BEligible duration for assignment
  3. CMaximum activation duration
  4. DRequire justification on activation
Show answer & explanation

Correct answer: C. Maximum activation duration

The 'Maximum activation duration' setting directly controls how long a role can remain active after a user has activated it. Setting this to 4 hours ensures automatic de-assignment after that period.

Why the other options are wrong

  • A. This refers to settings for roles that are permanently assigned, not for time-limited eligible assignments.
  • B. This setting controls how long a user is *eligible* for a role, not how long it remains *active* once activated.
  • D. This setting requires a reason for activation, but does not control the duration of the active assignment.

PIM Maximum Activation Duration

A Microsoft Entra PIM setting that specifies the maximum time a privileged role can be active after a user activates it, enforcing Just-In-Time (JIT) access principles.

  • Limits the window of elevated privilege.
  • Automatically deactivates the role after the set duration.
  • Typically set to a short period (e.g., 1-8 hours) for critical roles.

Memory trick: Activation has a timer, eligibility has its own.

More Implement access governance questions