Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

SC-900 Describe the capabilities of Microsoft Entra Practice Question

A company uses Microsoft Entra ID Privileged Identity Management (PIM) to manage elevated access to Microsoft Entra ID roles. They want to ensure that a user who activates a privileged role must provide a justification and receive approval from their manager before activation is complete. Which PIM configuration should be used?

⚠ Common exam trap

Watch out — candidates often confuse 'require approval' with 'require MFA' or 'require compliant device,' not realizing that only the approval setting introduces a separate review step by another person, which is explicitly needed for manager authorization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure role settings to require approval on activation

Microsoft Entra ID Privileged Identity Management (PIM) allows administrators to configure role settings that require approval before a role is activated. By enabling the 'Require approval to activate' setting, a designated approver (such as the user's manager) must review and approve the activation request, ensuring that the justification is validated before access is granted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure role settings to require multi-factor authentication on activation

    Why it's wrong here

    While requiring multi-factor authentication (MFA) during role activation significantly enhances security by verifying the user's identity, it does not introduce an approval workflow. MFA is an authentication mechanism that confirms the legitimate user is performing the action, but it does not involve a separate party, such as a manager, reviewing and explicitly authorizing the activation request. Therefore, it fails to meet the requirement for an approval step.

  • Configure role settings to require approval on activation

    Why this is correct

    Configuring role settings to require approval on activation directly addresses the need for a manager to authorize privileged access. When a user attempts to activate a role, Microsoft Entra ID PIM routes the request to predefined approvers, who are typically managers or security administrators. The role remains inactive until at least one designated approver explicitly grants permission, ensuring an independent review and authorization before elevated privileges are granted.

  • Configure role settings to assign the user as permanently active

    Why it's wrong here

    Assigning a user as permanently active for a privileged role completely bypasses the just-in-time (JIT) access principles central to Microsoft Entra ID PIM. With a permanent assignment, the user always possesses the elevated permissions, eliminating any requirement for activation, justification, or, critically, an approval workflow. This configuration directly contradicts the goal of controlling and reviewing temporary access to sensitive roles.

  • Configure role settings to require an Microsoft Entra ID compliant device

    Why it's wrong here

    Requiring an Microsoft Entra ID compliant device for role activation is a conditional access policy that ensures the user's endpoint meets specific security standards, such as having up-to-date antivirus or being encrypted. While this enhances the security posture of the activation process, it functions as an automated prerequisite rather than an explicit approval step. If the device meets the compliance criteria, the activation proceeds without requiring a human approver to review and authorize the request.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.