mediumMultiple Choice
MS-102 Practice Question: A company with Microsoft Entra ID P2 licenses…
A company with Microsoft Entra ID P2 licenses wants to enforce that all activations of the Global Administrator role require approval from a designated security group. The activation must also require a business justification and expire after 4 hours. Which Microsoft Entra ID feature should the administrator configure?
⚠ Common exam trap
It's easy for candidates to confuse Conditional Access (which controls sign-in conditions) with PIM (which controls role activation), leading them to select Option C because they think 'approval' is a conditional access policy, but PIM is the only feature that manages role activation workflows and expiration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Privileged Identity Management (PIM)
Microsoft Entra Privileged Identity Management (PIM) provides time-bound and approval-based role activation. It allows you to require approval from a designated security group, mandate a business justification, and set a maximum activation duration (e.g., 4 hours) for privileged roles like Global Administrator. This directly matches all the requirements in the question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID Protection
Why it's wrong here
Microsoft Entra ID Protection analyzes signals to detect risky sign-ins and user behavior, classifying them as low, medium, or high risk. It can enforce risk-based policies such as requiring MFA or blocking access, but it has no concept of role activation or an approval workflow. It cannot require a designated approver to authorize an Microsoft Entra ID role becoming active for a specific time window.
- ✓
Microsoft Entra Privileged Identity Management (PIM)
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) provides just-in-time activation of Microsoft Entra ID roles, implementing a request-and-approval workflow that aligns exactly with the stated requirement. Through PIM, you can require users to submit an activation request with justification, designate eligible approvers, and set a maximum activation duration. It also supports time-bound assignments, MFA enforcement on activation, and full auditing of every role activation, making it the definitive solution for controlling privileged access.
- ✗
Microsoft Entra Conditional Access
Why it's wrong here
Microsoft Entra Conditional Access evaluates conditions such as user, location, device state, and risk to allow or restrict access to cloud apps and services via policies. It can require MFA, block access, or enforce session controls, but it operates at the sign-on and access layer, not on the entitlement of directory roles. Conditional Access has no mechanism for a user to request elevation, an approver to review it, or an expiration of the elevated permission.
- ✗
Microsoft Entra ID Multi-Factor Authentication
Why it's wrong here
Microsoft Entra ID Multi-Factor Authentication strengthens authentication by requiring a second verification factor, such as a phone call or authenticator app, during sign-in. While PIM can require MFA as part of the role activation process, MFA itself does not provide an approval workflow, role eligibility, or time-bound activation. It cannot enforce that a separate approver decides whether to grant a user the ability to assume a privileged role.
Go deeper
Related to this question
Learn chapter
Entra ID Access Reviews
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.