Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceHard
A defense contractor uses Microsoft Entra ID and has mandated that all 'Security Administrator' roles must be assigned as eligible, just-in-time (JIT) roles through PIM. Due to the highly sensitive nature of the data involved, every activation of this role must be approved by at least two separate senior security officers. This approval process must be multi-stage, where one officer approves, and then a second, different officer provides a final approval before the role is activated. Which PIM setting should be configured to achieve this multi-stage approval for 'Security Administrator' role activations?
- ARequire Azure AD Multi-Factor Authentication
- BMulti-stage approval workflow
- CRequire justification for activation
- DMaximum activation duration
Show answer & explanationAnswer & explanation
Correct answer: B. Multi-stage approval workflow
To enforce approval by two separate senior security officers in sequence, a 'Multi-stage approval workflow' must be configured within the PIM role settings. This allows defining distinct approvers for each stage.
Why the other options are wrong
- A. MFA is for authentication, not for defining multiple approval stages.
- C. Justification is a text field, not an approval workflow.
- D. Maximum activation duration controls how long the role is active, not the approval process itself.
PIM Multi-Stage Approval
A PIM setting that allows defining a sequential approval workflow with multiple distinct approvers, where each stage must be approved before the privileged role can be activated.
- Enhances security for critical role activations by requiring multiple sign-offs.
- Each stage can have different approvers.
- Provides a stronger control plane for highly sensitive roles.
Memory trick: PIM approval: a chain of command, multiple 'yes' needed.