Courseiva
Secure identity and access →mediumMultiple Choice

AZ-500 Secure identity and access Practice Question

You are designing a privileged identity management strategy for Microsoft Entra ID. You need to ensure that eligible role assignments require approval from a designated group before activation. What configuration is required?

⚠ Common exam trap

Many candidates confuse Conditional Access approval controls (used for session policies) with PIM role activation approval, which is a separate configuration within the role settings in Privileged Identity Management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In PIM, configure the role settings to require approval and specify an approver group

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure role settings to require approval for activation. By specifying an approver group, you ensure that eligible role assignments cannot be activated without explicit approval from designated members, enforcing a just-in-time (JIT) access control model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the role as eligible and set activation duration

    Why it's wrong here

    Setting a role to eligible merely allows the user to activate on demand; the activation duration controls how long that temporary assignment lasts once activated. Activating an eligible role without an approval requirement is a self-service action completed by the user, with no approver or review step. PIM's activation settings have a separate 'Require approval to activate' toggle that must be enabled to introduce an approval gate—eligibility alone does not create one.

  • ✗

    Configure a Conditional Access policy with approval control

    Why it's wrong here

    Conditional Access policies evaluate conditions at sign-in—such as device compliance, location, or MFA—and are enforced before a user can access an application or service. They cannot act as the PIM activation approval workflow because PIM activation happens after authentication and does not surface a standard sign-in event for Conditional Access to gate. PIM approval is managed in role settings, not by Conditional Access, so this approach would never route a request to an approver for review.

  • ✓

    In PIM, configure the role settings to require approval and specify an approver group

    Why this is correct

    In PIM, open the role's Activation settings, enable 'Require approval to activate', and specify one or more approvers or an approver group. When an eligible member activates the role, the request is sent to those approvers, who approve or deny via the Microsoft Entra admin center or email notification. The role becomes active only after approval is granted, and you can also require justification as part of the activation request, creating a full audit trail.

  • ✗

    Create an access review for the role

    Why it's wrong here

    Access reviews in PIM are scheduled, recurring audits where reviewers validate whether users still need eligible or active assignments—they are designed to remove stale access over time, not to gate each individual activation request. A user can activate an eligible role multiple times between access review cycles without any per-activation approval. Therefore, an access review does not satisfy the requirement that a separate approver approve the role activation itself.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.