AZ-500 Secure identity and access Practice Question
You are designing a privileged identity management strategy for Microsoft Entra ID. You need to ensure that eligible role assignments require approval from a designated group before activation. What configuration is required?
⚠ Common exam trap
Many candidates confuse Conditional Access approval controls (used for session policies) with PIM role activation approval, which is a separate configuration within the role settings in Privileged Identity Management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In PIM, configure the role settings to require approval and specify an approver group
Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure role settings to require approval for activation. By specifying an approver group, you ensure that eligible role assignments cannot be activated without explicit approval from designated members, enforcing a just-in-time (JIT) access control model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the role as eligible and set activation duration
Why it's wrong here
Setting a role to eligible merely allows the user to activate on demand; the activation duration controls how long that temporary assignment lasts once activated. Activating an eligible role without an approval requirement is a self-service action completed by the user, with no approver or review step. PIM's activation settings have a separate 'Require approval to activate' toggle that must be enabled to introduce an approval gate—eligibility alone does not create one.
- ✗
Configure a Conditional Access policy with approval control
Why it's wrong here
Conditional Access policies evaluate conditions at sign-in—such as device compliance, location, or MFA—and are enforced before a user can access an application or service. They cannot act as the PIM activation approval workflow because PIM activation happens after authentication and does not surface a standard sign-in event for Conditional Access to gate. PIM approval is managed in role settings, not by Conditional Access, so this approach would never route a request to an approver for review.
- ✓
In PIM, configure the role settings to require approval and specify an approver group
Why this is correct
In PIM, open the role's Activation settings, enable 'Require approval to activate', and specify one or more approvers or an approver group. When an eligible member activates the role, the request is sent to those approvers, who approve or deny via the Microsoft Entra admin center or email notification. The role becomes active only after approval is granted, and you can also require justification as part of the activation request, creating a full audit trail.
- ✗
Create an access review for the role
Why it's wrong here
Access reviews in PIM are scheduled, recurring audits where reviewers validate whether users still need eligible or active assignments—they are designed to remove stale access over time, not to gate each individual activation request. A user can activate an eligible role multiple times between access review cycles without any per-activation approval. Therefore, an access review does not satisfy the requirement that a separate approver approve the role activation itself.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.