A company uses Azure AD Privileged Identity Management (PIM) for the Global Administrator role. They have configured the role activation to require approval from a specific security group. When a user attempts to activate the role, they are immediately approved without any approval request being sent. The user is a member of the same security group that is configured as the approver. What is the most likely cause?
Trap 1: The activation approval requirement is not supported for the Global…
PIM's approval workflow is fully supported for the Global Administrator role, just as it is for every built-in and custom Microsoft Entra ID role. This misconception often stems from the fact that Global Administrators have broad tenant permissions, including the ability to manage PIM itself, but that does not exempt the role from enforcement of an approval requirement. Because the option states the requirement is 'not supported,' it is incorrect.
Trap 2: The user is a member of the approver group and is self-approving…
In PIM, a user who is a member of an approver group can approve their own activation request unless the policy setting 'Disable approver approval' has been explicitly enabled. Since the scenario does not indicate this setting is enabled, self-approval is permitted, which means the request can be approved immediately by the user themselves. This bypasses the intent of separation of duties but is a known and expected PIM behavior.
Trap 3: The role activation duration is set to zero, causing immediate…
The role activation duration setting controls how long the role is active after an activation is approved, not whether an approval is needed. Setting the duration to zero—or any other value—does not bypass the approval workflow; the activation request still must be approved before the role becomes active. Thus, this option incorrectly conflates two independent policy settings and is not a valid reason for bypassing approval.
- A
The activation approval requirement is not supported for the Global Administrator role
Why it fails: PIM's approval workflow is fully supported for the Global Administrator role, just as it is for every built-in and custom Microsoft Entra ID role. This misconception often stems from the fact that Global Administrators have broad tenant permissions, including the ability to manage PIM itself, but that does not exempt the role from enforcement of an approval requirement. Because the option states the requirement is 'not supported,' it is incorrect.
- B
The user is a member of the approver group and is self-approving the request
Why it fails: In PIM, a user who is a member of an approver group can approve their own activation request unless the policy setting 'Disable approver approval' has been explicitly enabled. Since the scenario does not indicate this setting is enabled, self-approval is permitted, which means the request can be approved immediately by the user themselves. This bypasses the intent of separation of duties but is a known and expected PIM behavior.
- C
The PIM policy has not been activated for the Global Administrator role
PIM policies are effective as soon as they are configured; there is no separate 'activation' step that must be performed on a policy before it governs role assignments. Once a role's policy is saved, the approval requirement, duration, and other settings are active and applied to eligible assignments. Therefore, the claim that the policy 'has not been activated' is not a valid explanation for why approval was skipped.
- D
The role activation duration is set to zero, causing immediate activation
Why it fails: The role activation duration setting controls how long the role is active after an activation is approved, not whether an approval is needed. Setting the duration to zero—or any other value—does not bypass the approval workflow; the activation request still must be approved before the role becomes active. Thus, this option incorrectly conflates two independent policy settings and is not a valid reason for bypassing approval.