Which TWO features are available in Microsoft Entra ID Privileged Identity Management (PIM) for managing Azure AD roles? (Choose two.)
Just-in-time activation is a core PIM capability that lets administrators make eligible roles available for temporary, time-boxed elevation. When a user needs elevated privileges, they activate the role for a specific duration, often with a justification, MFA check, and optional scope constraints. This reduces standing access and implements the principle of least privilege.
Why this answer
Option B (Just-in-time activation) is correct because PIM's core capability is making users eligible for Azure AD roles and requiring them to activate the role only when needed, granting time-bound, temporary elevation instead of permanent assignment. Option E (Approval workflow for role activation) is correct because PIM role settings allow administrators to require approval before an eligible user's activation request is granted, with designated approvers reviewing the request. The other options do not belong: self-service password reset (A) is an Entra ID authentication feature, not a PIM role-management feature; multi-factor authentication enforcement (C) is configured via Conditional Access or authentication methods, not as a PIM role feature; and automatic role assignment based on group membership (D) is handled by group-based licensing/role-assignable groups, not by PIM activation.
Exam trap
The trap here is that candidates often confuse features that are integrated with PIM (like MFA enforcement and self-service password reset) as being features of PIM itself, when in fact PIM's core capabilities are just-in-time activation and approval workflows for role activation.