AZ-500 Secure identity and access Practice Question
Which TWO features are available in Microsoft Entra ID Privileged Identity Management (PIM) for managing Microsoft Entra ID roles? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse features that are integrated with PIM (like MFA enforcement and self-service password reset) as being features of PIM itself, when in fact PIM's core capabilities are just-in-time activation and approval workflows for role activation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Just-in-time activation
Option B (Just-in-time activation) is correct because PIM's core capability is making users eligible for Microsoft Entra ID roles and requiring them to activate the role only when needed, granting time-bound, temporary elevation instead of permanent assignment. Option E (Approval workflow for role activation) is correct because PIM role settings allow administrators to require approval before an eligible user's activation request is granted, with designated approvers reviewing the request. The other options do not belong: self-service password reset (A) is an Entra ID authentication feature, not a PIM role-management feature; multi-factor authentication enforcement (C) is configured via Conditional Access or authentication methods, not as a PIM role feature; and automatic role assignment based on group membership (D) is handled by group-based licensing/role-assignable groups, not by PIM activation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Self-service password reset
Why it's wrong here
Self-service password reset is an Entra ID feature that allows end users to reset their own forgotten passwords without help desk involvement. It is not part of Privileged Identity Management, which focuses on managing, activating, and overseeing privileged administrative roles. While both are security-related, SSPR addresses user credential self-recovery rather than temporary elevation of role permissions.
- ✓
Just-in-time activation
Why this is correct
Just-in-time activation is a core PIM capability that lets administrators make eligible roles available for temporary, time-boxed elevation. When a user needs elevated privileges, they activate the role for a specific duration, often with a justification, MFA check, and optional scope constraints. This reduces standing access and implements the principle of least privilege.
- ✗
Multi-factor authentication enforcement
Why it's wrong here
Multi-factor authentication enforcement is a general Entra ID security policy applicable to all users, not a feature exclusive to PIM. PIM can require MFA as a condition during role activation, but that merely invokes the existing conditional access or authentication controls. It is not a distinct PIM feature; it is an integration point with broader identity security posture.
- ✗
Automatic role assignment based on group membership
Why it's wrong here
Automatic role assignment based on group membership is a misunderstanding of how PIM handles groups. While you can add a group as a role-assignable group in PIM, members become eligible for the role, but activation still requires a manual, time-boxed activation through the PIM workflow. PIM does not automatically grant active role assignment solely based on group membership.
- ✓
Approval workflow for role activation
Why this is correct
Approval workflow for role activation is a built-in PIM control that requires designated approvers to review and approve each activation request before the requested role is activated. This adds a human approval step to prevent unauthorized or excessive privilege elevation. It is a distinguishing feature of PIM compared to standard role assignments.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.