Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceHard

A financial institution uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for managing access to sensitive Azure resources. They have a custom Azure role, 'Financial Data Auditor', which requires an additional layer of verification upon activation. The policy states that users activating this role must securely confirm their identity using a certificate-based authentication method, in addition to their standard password. Which PIM setting, when configured for the 'Financial Data Auditor' role, would enforce this requirement?

  1. ARequire maximum activation duration
  2. BRequire approval to activate
  3. CRequire multi-factor authentication on activation
  4. DRequire justification on activation
Show answer & explanation

Correct answer: C. Require multi-factor authentication on activation

The 'Require multi-factor authentication on activation' setting in PIM mandates that users perform an MFA challenge when activating an eligible role. Certificate-based authentication (CBA) is a strong form of MFA supported by Microsoft Entra ID, and configuring this PIM setting would enforce the requirement for CBA during activation if CBA is configured as an MFA method in the tenant.

Why the other options are wrong

  • A. Maximum activation duration controls how long the role is active, not the authentication method for activation.
  • B. Approval involves another user, not a secure identity confirmation by the activating user.
  • D. Justification is for auditing, not for identity verification through CBA.

PIM MFA for Activation (with CBA)

A PIM setting that requires users to complete a multi-factor authentication challenge, potentially using methods like certificate-based authentication (CBA), during the activation of an eligible role.

  • Enhances security during role activation.
  • Can leverage strong MFA methods like CBA.
  • Protects against compromised credentials.

Memory trick: PIM Secures Activation with Strong ID.

More Implement access governance questions