mediumMultiple Choice
MS-102 Practice Question: Implement just-in-time (JIT) privileged access…
A company wants to implement just-in-time (JIT) privileged access for the Security Administrator role. Users must be able to activate the role with a business justification, and the activation must be approved by a designated group of approvers. The role activation should expire after 4 hours. Which Privileged Identity Management (PIM) configuration should the administrator modify?
⚠ Common exam trap
Many candidates confuse 'assignments' (who can use the role) with 'role settings' (how the role can be activated), leading them to choose Eligible assignments instead of Role settings when asked about activation policies like duration, approval, or justification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Role settings for the Security Administrator role
To configure just-in-time (JIT) privileged access with approval, expiration, and justification requirements, you must modify the Role settings for the Security Administrator role in Privileged Identity Management (PIM). Role settings control activation parameters such as maximum activation duration (4 hours), whether approval is required, and whether justification is mandatory. This is the only place where these activation policies are defined.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Role settings for the Security Administrator role
Why this is correct
Role settings for the Security Administrator role in Privileged Identity Management (PIM) define the activation policy for that role. This is the primary control point for just-in-time (JIT) access because it specifies the maximum activation duration, whether an approval workflow is required, and whether users must provide a justification and pass Microsoft Entra MFA. Without properly configured role settings, eligible users could activate with weak or no controls, so this is the correct place to enforce JIT.
- ✗
Assignments (Eligible) for the Security Administrator role
Why it's wrong here
Eligible assignments make a user eligible to activate the Security Administrator role, but they only define who may elevate, not how or under what constraints. The actual JIT mechanics—such as approval requirements, activation time limits, justification fields, or MFA forcing—live entirely in the role settings. An eligible assignment combined with permissive role settings still leaves you with weak, uncontrolled activation, so eligible assignments alone do not implement JIT.
- ✗
Assignments (Active) for the Security Administrator role
Why it's wrong here
Active assignments provide continuous, standing access to the Security Administrator role without any activation step. Because the elevated permissions are always present, there is no elevation event where MFA, approval, or a time-bound window could be enforced, which directly defeats the goal of just-in-time access. To be JIT, users must be eligible rather than active, and the role settings must impose activation controls on top of that eligibility.
- ✗
Notifications settings under PIM
Why it's wrong here
Notifications settings under PIM govern email alerts for events like activation requests, approvals, role assignments, and elapsed-time warnings. These settings are purely informational and do not enforce or configure activation conditions—they only inform administrators about activity that has already occurred. While notifications complement a JIT strategy by improving monitoring and auditing, they are not the mechanism that implements JIT privileged access.
Go deeper
Related to this question
Learn chapter
Identity Lifecycle: Joiners, Movers, Leavers
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
Key term
Privileged Identity Management
Privileged Identity Management is a security system that controls, monitors, and audits access to sensitive systems by granting elevated permissions only when needed and for a limited time.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.