Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium

A company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for Azure AD roles. They have a critical role, 'Global Administrator', for which they want to enforce a policy where users must justify each activation and provide a support ticket number. This justification and ticket number must be reviewed by an approver before the role can be activated. Which PIM setting should be configured to meet these requirements?

  1. ARequire approval to activate
  2. BMaximum activation duration
  3. CRequire multi-factor authentication for activation
  4. DRequire justification on activation
Show answer & explanation

Correct answer: A. Require approval to activate

To enforce both justification and an approval workflow for PIM role activation, 'Require approval to activate' must be enabled. This setting allows you to specify approvers and ensures that justification (and optionally a ticket number) is provided and reviewed before activation.

Why the other options are wrong

  • B. This setting defines the maximum time a role can be active, not the approval process.
  • C. This setting enforces MFA, but does not include justification or an approval workflow.
  • D. While 'Require justification on activation' is part of the approval settings, it is a sub-setting of 'Require approval to activate'. Enabling only justification without approval would not meet the requirement for review by an approver.

PIM Approval Workflow

A security control in Microsoft Entra Privileged Identity Management (PIM) that mandates an approval process before users can activate eligible privileged roles, often requiring justification and/or a support ticket.

  • Enhances security by adding human oversight to sensitive role activations.
  • Can be configured with single or multiple approvers.
  • Includes options to require justification and/or a support ticket number.

Memory trick: PIM activates securely with approval's key.

More Implement access governance questions