Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy
A financial institution uses Microsoft Entra ID (formerly Azure Active Directory) and has a strict policy requiring all highly privileged Azure AD roles to be assigned on a just-in-time (JIT) basis. They want to ensure that eligible assignments for these roles expire automatically after a set period, forcing users to re-request access regularly. Which setting in Privileged Identity Management (PIM) should be configured to achieve this?
- ARequire approval to activate
- BMaximum activation duration
- CRequire multi-factor authentication on activation
- DAssignment duration for eligible assignments
Show answer & explanationAnswer & explanation
Correct answer: D. Assignment duration for eligible assignments
To ensure eligible assignments for highly privileged roles expire automatically after a set period, the 'Assignment duration for eligible assignments' setting in PIM should be configured. This setting controls how long a user remains eligible to activate the role.
Why the other options are wrong
- A. Require approval to activate controls whether an approval workflow is needed for role activation, not the eligibility duration.
- B. Maximum activation duration sets the maximum time a role can be active after activation, not the eligibility period.
- C. Require multi-factor authentication on activation enforces MFA during the activation process, not the duration of eligibility.
PIM Assignment Duration for Eligible Assignments
This PIM setting defines how long a user remains eligible to activate a privileged role before their eligibility expires, requiring a new request for assignment.
- Applies to eligible assignments, not active assignments.
- Forces re-evaluation of need for privilege.
- Can be set to a specific time period (e.g., 1 year, 90 days).
Memory trick: Eligibility clock for PIM roles.