Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy
A manufacturing company uses Microsoft Entra ID and has implemented PIM for Azure AD roles. They want to ensure that if a user activates a highly privileged role, they are automatically de-assigned from that role after a maximum of 4 hours, regardless of whether they explicitly deactivate it. Which PIM setting should be configured to enforce this strict time limit for active role assignments?
- APIM role settings for permanent assignments
- BEligible duration for assignment
- CMaximum activation duration
- DRequire justification on activation
Show answer & explanationAnswer & explanation
Correct answer: C. Maximum activation duration
The 'Maximum activation duration' setting directly controls how long a role can remain active after a user has activated it. Setting this to 4 hours ensures automatic de-assignment after that period.
Why the other options are wrong
- A. This refers to settings for roles that are permanently assigned, not for time-limited eligible assignments.
- B. This setting controls how long a user is *eligible* for a role, not how long it remains *active* once activated.
- D. This setting requires a reason for activation, but does not control the duration of the active assignment.
PIM Maximum Activation Duration
A Microsoft Entra PIM setting that specifies the maximum time a privileged role can be active after a user activates it, enforcing Just-In-Time (JIT) access principles.
- Limits the window of elevated privilege.
- Automatically deactivates the role after the set duration.
- Typically set to a short period (e.g., 1-8 hours) for critical roles.
Memory trick: Activation has a timer, eligibility has its own.