Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceHard
A healthcare provider uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. They have a strict policy that all 'User Administrator' role activations must be reviewed by a specific security team. The review process should involve two distinct stages: an initial review by a Tier 1 Security Analyst, followed by a final approval from a Tier 2 Security Operations Lead. Both stages must be completed successfully before the role is activated. Which PIM setting should be configured to meet this multi-stage approval requirement?
- ARequire multi-stage approval to activate
- BRequire justification on activation
- CRequire approval to activate (with multiple approvers)
- DRequire multi-factor authentication on activation
Show answer & explanationAnswer & explanation
Correct answer: A. Require multi-stage approval to activate
PIM's 'Require multi-stage approval to activate' setting is specifically designed for scenarios where an activation request needs to pass through distinct, sequential approval stages, each with its own set of approvers. This perfectly matches the requirement for a Tier 1 review followed by a Tier 2 approval.
Why the other options are wrong
- B. Justification is for auditing, not for multi-stage approval.
- C. While 'Require approval to activate' allows multiple approvers, it typically implies parallel approval or any one of them approving, not distinct sequential stages.
- D. MFA is for user identity verification, not for an approval workflow.
PIM Multi-Stage Approval
A PIM feature that allows defining sequential approval stages for role activation, where each stage must be completed by designated approvers before the next stage begins.
- Enforces sequential approval steps.
- Each stage can have different approvers.
- Provides granular control over sensitive role activation.
Memory trick: Multi-Stage PIM Approvals are Like a Chain of Command.