mediumMultiple Choice
MS-102 Practice Question: A company uses Microsoft Entra Privileged…
A company uses Microsoft Entra Privileged Identity Management (PIM) for role activation. They want to require that any activation of the Security Administrator role be approved by a designated group of approvers called 'Security Approvers'. Activations must include a ticket number and expire after 8 hours. Which PIM configuration should the administrator modify?
⚠ Common exam trap
Test-takers frequently confuse role settings (which control activation policies) with role assignments (which control who can activate), leading candidates to mistakenly choose Option B when the question asks about activation requirements rather than eligibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role settings for Security Administrator
Microsoft Entra PIM role settings for a specific role, such as Security Administrator, control activation requirements including approval workflow, justification (ticket number), and maximum activation duration. By modifying the role settings, the administrator can require approval from the 'Security Approvers' group, mandate a ticket number, and set an 8-hour expiration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Role settings for Security Administrator
Why this is correct
In Microsoft Entra PIM (formerly Azure AD PIM), the Role settings blade for a specific role defines the activation policy: it allows you to configure 'Require approval to activate', 'Require justification on activation', 'Require Microsoft Entra ID MFA', and set the maximum activation duration. These settings are role-specific, so editing the Security Administrator role settings is exactly where you control how that role's eligible members activate privileged access. No other PIM area (assignments, reviews, alerts) modifies these activation requirements.
- ✗
Role assignments for Security Administrator
Why it's wrong here
PIM role assignments control which users are eligible or active for a role and whether an assignment is permanent or time-bound; they do not define activation rules. You can add or remove members, but the approval, justification, and duration constraints come solely from the role settings. Therefore, changing assignments only changes a user's status, not the activation workflow requirements.
- ✗
Access reviews for Security Administrator
Why it's wrong here
Access reviews in PIM are scheduled, cyclical attestation workflows where reviewers verify that each user still needs the Security Administrator role. They can expire or remove unnecessary eligible/active assignments after review, but they never specify activation parameters like required approvers or maximum activation time. So access reviews audit continued need for the role, not govern the initial activation process.
- ✗
Alerts for Security Administrator
Why it's wrong here
PIM alerts are rule-based or AI-driven notifications that flag suspicious or risky behavior, such as a user activating a role under unusual conditions or an unexpected role assignment. They help administrators respond to potential security incidents, but they do not configure activation requirements like approval or time limits. Alerts are reactive detection controls, whereas role settings are the proactive policy that defines activation rules.
Go deeper
Related to this question
Learn chapter
Entra ID Entitlement Management and Access Packages
Key term
Privileged Identity Management
Privileged Identity Management is a security system that controls, monitors, and audits access to sensitive systems by granting elevated permissions only when needed and for a limited time.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.