AZ-500 Manage identity and access Practice Question
A company uses Microsoft Entra Privileged Identity Management (PIM) to manage access to the 'Security Administrator' role. They want a specific user to be able to activate the role only when needed, rather than having standing access. The user should not have the role active at all times. Which type of assignment should they configure for this user in PIM?
⚠ Common exam trap
Candidates often confuse 'Active' (permanent standing access) with 'Eligible' (just-in-time activation), as candidates often think 'Active' means the user can activate the role, when in fact it means the role is always active.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the user as 'Eligible' for the role.
In Microsoft Entra Privileged Identity Management (PIM), an 'Eligible' assignment means the user does not have permanent access to the role. They must activate the role on-demand through a time-bound activation process, which may require approval and multi-factor authentication. This directly meets the requirement of having no standing access, as the role is inactive until the user explicitly activates it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the user as 'Active' for the role.
Why it's wrong here
An Active assignment in PIM grants the user the role immediately and continuously, without any need to activate it, which creates standing privileged access. Even a time-bound active assignment still does not require the user to perform an activation step at the moment of use. Since the requirement is to activate the role only when needed, this option fails to provide just-in-time access and actually increases the attack surface.
- ✓
Assign the user as 'Eligible' for the role.
Why this is correct
This is the correct approach because an Eligible assignment in PIM is a dormant state where the user has no effective role permissions until they activate it through the PIM portal or API. During activation, the user can be required to supply a business justification, pass Microsoft Entra ID Multi-Factor Authentication, and, if configured, receive approval from role approvers. The role then becomes active only for a limited, configurable duration, meaning privileged access exists exactly when needed and expires automatically.
- ✗
Assign the user as 'Permanent' for the role.
Why it's wrong here
There is no assignment type in PIM called 'Permanent'; the UI offers 'Eligible' or 'Active' as the assignment type and 'Permanent' or 'Time-bound' as the duration within either type. Choosing 'Permanent' as a standalone answer is meaningless, and if it is interpreted as a permanent Active assignment, it grants standing access without any activation requirement. Therefore, this option cannot satisfy the requirement for just-in-time activation of the privileged role.
- ✗
Add the user as a 'Guest' in the directory.
Why it's wrong here
Adding the user as a Guest in the directory only grants external user identity visibility for collaboration in Microsoft Entra ID, Microsoft Teams, or SharePoint; it does not assign any Microsoft Entra ID role. Guest users are not inherently given privileged role assignments, and this action is unrelated to and insufficient for the requirement to provide just-in-time access. If the user is an employee, they should already be an internal member; adding them as a guest would not even give them a work identity in the tenant's directory.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.