Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceHard

A financial services organization uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. Due to stringent regulatory requirements, all activations of highly privileged roles, such as 'Global Administrator' or 'Privileged Role Administrator', must be digitally signed by the requesting administrator using a certificate-based credential. Which PIM setting, in conjunction with other Microsoft Entra features, would allow this secure activation method?

  1. ARequire justification on activation
  2. BRequire multi-factor authentication on activation
  3. CRequire active assignment
  4. DRequire approval to activate
Show answer & explanation

Correct answer: B. Require multi-factor authentication on activation

While 'Require multi-factor authentication on activation' is the direct PIM setting, the scenario specifies 'digitally signed by the requesting administrator using a certificate-based credential'. In Microsoft Entra ID, certificate-based authentication (CBA) can be configured as a strong authentication method, which PIM can then enforce as part of its MFA requirement for activation. This is a nuanced application of MFA.

Why the other options are wrong

  • A. Requiring justification adds a text field but doesn't enforce a digital signature or strong authentication.
  • C. Requiring active assignment means the role is permanently assigned, bypassing the activation process entirely, which contradicts the scenario's focus on activation.
  • D. Requiring approval adds a human approval step but doesn't enforce the requesting user's digital signature for activation.

PIM MFA with Certificate-Based Authentication

The PIM setting 'Require multi-factor authentication on activation' can enforce strong authentication methods like Certificate-Based Authentication (CBA) configured in Microsoft Entra ID, enabling digital signing for privileged role activations.

  • MFA can be satisfied by various credential types, including CBA.
  • CBA provides a strong, cryptographically backed identity proof.
  • PIM leverages Entra ID's authentication policies for activation.

Memory trick: MFA is the key, and a certificate makes it extra secure, you see.

More Implement access governance questions