Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium
A global manufacturing company uses Microsoft Entra ID and has implemented Privileged Identity Management (PIM) for its Azure AD roles. They have a critical role, 'Global Admin', which requires an additional layer of security before activation. Specifically, any activation of the 'Global Admin' role must be approved by at least two designated security managers. This approval should happen even if the requesting user is already eligible for the role. Which PIM setting should be configured to enforce this requirement?
- ARequire justification on activation
- BRequire approval to activate
- CRequire MFA on activation
- DRequire maximum activation duration
Show answer & explanationAnswer & explanation
Correct answer: B. Require approval to activate
The 'Require approval to activate' setting in PIM allows you to designate specific approvers (users or groups) who must approve a request before a user can activate an eligible role assignment. This directly addresses the need for two security managers to approve activation.
Why the other options are wrong
- A. Requiring justification is for auditing purposes, not for enforcing multi-person approval.
- C. Requiring MFA adds a security layer for the user, but doesn't involve additional approvers.
- D. Maximum activation duration controls how long the role can be active, not the approval process for activation.
PIM Approval Workflow
A Privileged Identity Management feature that mandates designated approvers to review and approve requests for role activation, enhancing security for critical roles.
- Adds an approval step before role activation.
- Can specify individual users or groups as approvers.
- Enhances control over sensitive role assignments.
Memory trick: PIM Approves Critical Roles with Care.