Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium
A large multinational corporation uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for several Azure AD roles. The security team wants to ensure that all activations of the 'Global Administrator' role are accompanied by a multi-factor authentication (MFA) challenge, even if the user has already satisfied MFA during their initial sign-in to Microsoft Entra ID. This is to provide an additional layer of security for highly privileged actions. Which PIM setting for the 'Global Administrator' role is required to enforce this behavior?
- ARequire justification for activation
- BRequire Azure AD Multi-Factor Authentication
- CRequire approval to activate
- DRequire maximum activation duration
Show answer & explanationAnswer & explanation
Correct answer: B. Require Azure AD Multi-Factor Authentication
To enforce an MFA challenge specifically for PIM role activation, even if MFA was already completed for sign-in, the 'Require Azure AD Multi-Factor Authentication' setting must be enabled within the PIM role settings.
Why the other options are wrong
- A. Justification is a text field and does not enforce an MFA challenge.
- C. Approval requires another user to approve the activation, not an MFA challenge.
- D. Maximum activation duration controls how long a role can be active, not the authentication method for activation.
PIM MFA for Activation
A PIM setting that mandates a Multi-Factor Authentication challenge specifically during the activation of a privileged role, regardless of whether the user has already performed MFA for their initial sign-in.
- Enhances security for highly sensitive role activations.
- Provides 'just-in-time' MFA for privileged actions.
- Configured per role within PIM settings.
Memory trick: PIM role activation: MFA is the guardian's key.