AZ-500 Manage identity and access Practice Question
A company uses Microsoft Entra Privileged Identity Management (PIM) to manage the 'Security Administrator' role. They want a user to be able to activate this role for a maximum of 2 hours per activation. Which PIM setting should they configure?
⚠ Common exam trap
Candidates often confuse 'Activation maximum duration' (the time a role is active after activation) with 'Expire eligible assignments after' (the time a user remains eligible to activate), leading candidates to incorrectly choose Option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the 'Activation maximum duration' to 2 hours in the role settings for Security Administrator.
The 'Activation maximum duration' setting in Microsoft Entra PIM role settings directly controls the maximum time a user can remain active in an eligible role after activation. By setting this to 2 hours, the user will be able to activate the Security Administrator role for up to 2 hours per activation, after which the role assignment expires automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the 'Activation maximum duration' to 2 hours in the role settings for Security Administrator.
Why this is correct
The 'Activation maximum duration' in the role settings for Security Administrator directly defines the maximum time a user can remain active in that role after requesting activation. By setting it to 2 hours, you guarantee that any single activation session expires after two hours, at which point the user's role assignment is deactivated unless they reactivate. This is the specific setting that enforces the 2-hour limit requested by the company.
- ✗
Set the 'Expire eligible assignments after' to 2 hours in the role settings.
Why it's wrong here
'Expire eligible assignments after' determines how long a user can remain eligible to activate the role before their eligibility assignment itself expires. It does not govern the length of an activation session; even with a 2-hour eligibility timeframe, once activated, the user could remain active for the full duration allowed by the activation maximum duration setting. Therefore, this setting controls the assignment lifecycle, not the session length, and cannot be used to enforce a 2-hour activation cap.
- ✗
Enable 'Require justification' and 'Require approval' to ensure the role is not misused.
Why it's wrong here
Enabling 'Require justification' and 'Require approval' adds governance and oversight to the activation request process, ensuring that users provide a reason and receive managerial consent before the role is activated. However, these controls do not impose any time bound on the resulting activation session; after approval, the user would remain active for whatever the 'Activation maximum duration' is set to. Thus, while these settings address misuse and accountability, they are orthogonal to the requirement of limiting activation duration to 2 hours.
- ✗
Set the 'Activation maximum duration' to 1 hour and the user can activate twice.
Why it's wrong here
Setting 'Activation maximum duration' to 1 hour means each activation can last at most one hour, but PIM does not prevent the user from starting a new activation immediately after the previous one expires. If the user activates twice, the total time with the role could exceed 2 hours, potentially reaching 2 hours of accumulated active time or more depending on the timing. The correct configuration is to set the maximum duration to 2 hours per activation, which directly caps a single session at the required limit.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.