Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceEasy

A software development company uses Microsoft Entra ID and has implemented PIM for its Azure AD roles. The security team observes that 'Global Administrator' role activations frequently exceed the intended duration, leading to prolonged elevated privileges. They want to ensure that once a 'Global Administrator' role is activated, it is automatically deactivated after a strict maximum period of 4 hours, regardless of whether the user remembers to deactivate it manually. Which PIM setting for the 'Global Administrator' role should be configured to enforce this policy?

  1. ARequire justification for activation
  2. BRequire approval to activate
  3. CRequire Azure AD Multi-Factor Authentication
  4. DMaximum activation duration
Show answer & explanation

Correct answer: D. Maximum activation duration

The 'Maximum activation duration' setting in PIM directly controls how long a privileged role remains active after activation. Setting this to 4 hours will ensure automatic deactivation after that period.

Why the other options are wrong

  • A. Justification is a text input, not a time limit.
  • B. Approval controls who can activate, not how long the role stays active.
  • C. MFA is for authentication during activation, not for the duration of the active role.

PIM Maximum Activation Duration

A PIM setting that specifies the maximum amount of time a user can have an activated privileged role before it is automatically deactivated.

  • Enforces 'just-in-time' access by limiting active privilege time.
  • Helps reduce the attack surface by minimizing exposure of privileged roles.
  • Configurable per role in PIM settings.

Memory trick: PIM timer: roles expire, security gains.

More Implement access governance questions