AZ-500 Secure identity and access Practice Question
Which TWO of the following are required to implement a successful Just-In-Time (JIT) access strategy using Microsoft Entra Privileged Identity Management (PIM) for Azure resources?
⚠ Common exam trap
A common mix-up: candidates confuse enabling MFA tenant-wide (Option A) with PIM's ability to require MFA at activation time, which is a separate setting within the role activation policy, not a prerequisite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure role settings to specify activation duration and require approval if needed
Option C is correct because PIM role settings define the activation parameters that make access just-in-time, such as maximum activation duration, whether approval is required, and whether justification or MFA is needed at activation; without configuring these settings, eligible assignments would not enforce time-bound, controlled activation. Option D is correct because JIT access in PIM for Azure resources requires users to be assigned as eligible for the Azure RBAC roles they need, so they can activate the role only when required rather than holding standing access. Option A is not required for the JIT strategy itself, since MFA can be enforced as a role setting at activation rather than mandating MFA for all tenant users. Option B is not required because PIM works with built-in Azure RBAC roles and custom roles are not a prerequisite for JIT access. Option E is incorrect because permanently active assignments provide standing access, which is the opposite of just-in-time access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Azure Multi-Factor Authentication for all users in the tenant
Why it's wrong here
Enabling Azure Multi-Factor Authentication for all users in the tenant is not a prerequisite for implementing JIT access with PIM. While you can (and often should) require MFA during role activation by configuring the role settings or Conditional Access policies, tenant-wide MFA enforcement is an identity security baseline, not a component specific to PIM's JIT model. The two essential elements are eligibility assignments and correctly configured activation policies, not a global MFA enablement.
- ✗
Create custom RBAC roles for the JIT access
Why it's wrong here
Creating custom RBAC roles is unnecessary for a JIT access strategy. PIM supports eligibility and activation for any Azure RBAC role, including built-in roles like Contributor or Security Admin; custom roles may be useful for least-privilege scoping, but they are not a requirement to implement JIT. The core requirements are defining activation parameters in role settings and making users eligible for the roles they need, so custom role definitions are orthogonal to the JIT mechanism.
- ✓
Configure role settings to specify activation duration and require approval if needed
Why this is correct
Configuring role settings is a required step because these settings define the operational parameters of JIT activation, such as the maximum activation duration (e.g., 1 hour), whether approval is required, and whether justification and ticket information are mandatory. Without these settings, PIM cannot enforce time-bound activation or control the approval workflow, so the JIT strategy would lack governance. You must explicitly configure the settings for each role that you plan to manage with PIM.
- ✓
Assign users as eligible for the roles they need to activate
Why this is correct
Assigning users as eligible for the roles they need is the fundamental requirement for a JIT strategy, because eligibility means the user has no standing access until they activate the role for a limited, policy-controlled period. PIM distinguishes between 'eligible' and 'active' assignments; only eligible assignments require activation, and activation triggers the JIT workflow that may include justification, MFA, and approval. Without eligible assignments, there would be nothing to activate and no JIT-based access control.
- ✗
Assign users as permanently active for the roles they need
Why it's wrong here
Assigning users as permanently active for the roles they need directly undermines JIT access, because it grants standing access around the clock and eliminates the need to activate the role. This configuration bypasses the activation workflow, including time limits, approvals, and justifications, making it functionally identical to static RBAC assignments. In a JIT model, you make users eligible, never permanently active, to ensure access exists only when actually required.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.