Courseiva

AZ-500 Manage identity and access Practice Question

You are the Azure Security Engineer for a company that uses Microsoft Entra ID. The security team wants to enforce that any user who is assigned the 'Privileged Role Administrator' role must activate it through Privileged Identity Management (PIM) with multi-factor authentication (MFA) and approval. You have already enabled PIM for the role. Which two actions must you perform to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that enabling PIM automatically enforces MFA and approval, or that conditional access can replace PIM activation settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the PIM role settings for 'Privileged Role Administrator', configure the 'Require multi-factor authentication on activation' setting to 'Yes'.

To enforce MFA and approval for PIM role activation, you must configure the role settings: set 'Require multi-factor authentication on activation' to 'Yes' and set 'Require approval to activate' with approvers. These settings apply to the role itself and are enforced when a user attempts activation. Other options like conditional access or eligible assignment do not meet the specific activation-time requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    In the PIM role settings for 'Privileged Role Administrator', configure the 'Require multi-factor authentication on activation' setting to 'Yes'.

    Why this is correct

    Enabling the MFA requirement in the PIM role settings forces users to perform MFA when they activate the role. This directly satisfies the MFA enforcement requirement. Without this setting, activation would not challenge the user for a second factor, leaving the privileged role vulnerable to credential compromise, even if the role is eligible and approval is required.

  • ✗

    Enable 'Just-in-time' (JIT) access for the role in PIM.

    Why it's wrong here

    JIT access is inherent to PIM when a role is assigned as eligible; it does not need to be separately enabled. It allows temporary activation but does not by itself enforce MFA or approval. The question already implies PIM is enabled, so JIT is not an additional action. The specific requirements are MFA and approval, which are separate settings.

  • ✓

    In the PIM role settings for 'Privileged Role Administrator', configure 'Require approval to activate' and specify at least one approver.

    Why this is correct

    Configuring approval to activate and designating approvers ensures that a user cannot activate the role without explicit approval. This meets the approval requirement. If no approvers are specified, the activation request cannot be approved, effectively blocking activation. This setting is separate from MFA and must be configured explicitly in the role settings.

  • ✗

    Assign the user as an eligible member of the 'Privileged Role Administrator' role.

    Why it's wrong here

    Making the user eligible is necessary for PIM activation, but it does not enforce MFA or approval. Eligibility alone allows the user to activate the role without additional controls. The question states that PIM is already enabled and the user is presumably already eligible; the requirements are about enforcing MFA and approval during activation, not about the assignment type.

  • ✗

    Create a conditional access policy that requires MFA for all users when they access the Azure portal.

    Why it's wrong here

    A conditional access policy requiring MFA for the Azure portal would enforce MFA at sign-in, but it does not specifically govern PIM role activation. PIM activation can occur via other interfaces, and the requirement is to enforce MFA at the moment of activation. Conditional access is broader and does not provide the approval workflow required.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.