AZ-500 Manage identity and access Practice Question
A company manages Microsoft Entra ID roles with Privileged Identity Management (PIM). They want to enforce that when a user activates the Global Administrator role, they must provide a justification and also use Multi-Factor Authentication. Which PIM settings should they configure? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse 'Require approval on activation' with 'Require justification on activation'—approval involves a separate approver, while justification is simply a text input from the user, and the question specifically asks for justification, not approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require Multi-Factor Authentication on activation.
PIM allows you to enforce Multi-Factor Authentication (MFA) as a mandatory step during role activation, ensuring the user's identity is verified beyond just a password. Option C is correct because PIM's 'Require justification on activation' setting forces the user to provide a business reason for activating the Global Administrator role, which is a common compliance requirement. Together, these two settings satisfy the requirement for both MFA and justification during activation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require approval on activation.
Why it's wrong here
Requiring approval on activation introduces a separate approval workflow in which a designated approver must review and approve the request before the role becomes active. While this is a valid PIM configuration, the scenario explicitly requires only justification and MFA, so adding an approval step is neither necessary nor sufficient to meet those stated security requirements.
- ✓
Require Multi-Factor Authentication on activation.
Why this is correct
Requiring Multi-Factor Authentication on activation forces the user to complete an MFA challenge during the activation request, such as through the Microsoft Authenticator app or a phone call, before the privileged role is assigned. This directly satisfies the security requirement for MFA on activation, and PIM evaluates this condition even if the user already has an existing Microsoft Entra ID session.
- ✓
Require justification on activation.
Why this is correct
Requiring justification on activation prompts the user to enter a business reason, like a support ticket number or explanation of the task, which PIM then logs as part of the activation audit trail. This fulfills the scenario's requirement for justification and ensures that every privileged role activation is attributable and compliant with internal policy.
- ✗
Extend activation duration.
Why it's wrong here
Extending activation duration changes how long a role remains active after successful activation, typically by configuring a maximum duration in hours for the eligible assignment. This setting does not address authentication or justification; it only widens the time window that privileges are available, so it cannot meet the specified requirements for MFA and justification.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.