Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy

A financial institution uses Microsoft Entra ID (formerly Azure Active Directory) and has a strict policy requiring all highly privileged Azure AD roles to be assigned on a just-in-time (JIT) basis. They want to ensure that eligible assignments for these roles expire automatically after a set period, forcing users to re-request access regularly. Which setting in Privileged Identity Management (PIM) should be configured to achieve this?

  1. ARequire approval to activate
  2. BMaximum activation duration
  3. CRequire multi-factor authentication on activation
  4. DAssignment duration for eligible assignments
Show answer & explanation

Correct answer: D. Assignment duration for eligible assignments

To ensure eligible assignments for highly privileged roles expire automatically after a set period, the 'Assignment duration for eligible assignments' setting in PIM should be configured. This setting controls how long a user remains eligible to activate the role.

Why the other options are wrong

  • A. Require approval to activate controls whether an approval workflow is needed for role activation, not the eligibility duration.
  • B. Maximum activation duration sets the maximum time a role can be active after activation, not the eligibility period.
  • C. Require multi-factor authentication on activation enforces MFA during the activation process, not the duration of eligibility.

PIM Assignment Duration for Eligible Assignments

This PIM setting defines how long a user remains eligible to activate a privileged role before their eligibility expires, requiring a new request for assignment.

  • Applies to eligible assignments, not active assignments.
  • Forces re-evaluation of need for privilege.
  • Can be set to a specific time period (e.g., 1 year, 90 days).

Memory trick: Eligibility clock for PIM roles.

More Implement access governance questions