Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium

A consulting firm uses Microsoft Entra ID and has implemented PIM for its Azure AD roles. They have a policy that consultants assigned to the 'Global Reader' role should only have eligible assignments for a maximum of 30 days. After this period, their eligibility should automatically expire, requiring a new request if access is still needed. Which PIM setting should be configured to enforce this policy?

  1. AMaximum assignment duration (eligible)
  2. BPermanent active assignments
  3. CMaximum activation duration
  4. DPermanent eligible assignments
Show answer & explanation

Correct answer: A. Maximum assignment duration (eligible)

The 'Maximum assignment duration (eligible)' setting in PIM controls how long a user can remain eligible for a role. After this duration, their eligible assignment is automatically removed, requiring them to re-request eligibility if needed. This directly addresses the 30-day limit for eligible assignments.

Why the other options are wrong

  • B. This option allows active assignments to last indefinitely, which is not about eligible assignments or a 30-day limit.
  • C. Maximum activation duration limits how long an eligible user can be *active* in the role after activating it, not how long they *remain eligible*.
  • D. This option allows eligible assignments to last indefinitely, which contradicts the 30-day limit.

PIM Eligible Assignment Duration

A PIM setting that specifies the maximum period a user can be eligible for a role before their eligibility automatically expires, promoting regular re-evaluation of access needs.

  • Controls duration of *eligible* assignments.
  • Ensures temporary eligibility for roles.
  • Requires re-request for continued eligibility.

Memory trick: PIM Durations Control Access Phases.

More Implement access governance questions