Courseiva
mediumMultiple Choice

MS-102 Practice Question: Implement just-in-time (JIT) privileged access…

A company wants to implement just-in-time (JIT) privileged access for the Security Administrator role. Users must be able to activate the role with a business justification, and the activation must be approved by a designated group of approvers. The role activation should expire after 4 hours. Which Privileged Identity Management (PIM) configuration should the administrator modify?

⚠ Common exam trap

Many candidates confuse 'assignments' (who can use the role) with 'role settings' (how the role can be activated), leading them to choose Eligible assignments instead of Role settings when asked about activation policies like duration, approval, or justification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Role settings for the Security Administrator role

To configure just-in-time (JIT) privileged access with approval, expiration, and justification requirements, you must modify the Role settings for the Security Administrator role in Privileged Identity Management (PIM). Role settings control activation parameters such as maximum activation duration (4 hours), whether approval is required, and whether justification is mandatory. This is the only place where these activation policies are defined.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Role settings for the Security Administrator role

    Why this is correct

    Role settings for the Security Administrator role in Privileged Identity Management (PIM) define the activation policy for that role. This is the primary control point for just-in-time (JIT) access because it specifies the maximum activation duration, whether an approval workflow is required, and whether users must provide a justification and pass Microsoft Entra MFA. Without properly configured role settings, eligible users could activate with weak or no controls, so this is the correct place to enforce JIT.

  • ✗

    Assignments (Eligible) for the Security Administrator role

    Why it's wrong here

    Eligible assignments make a user eligible to activate the Security Administrator role, but they only define who may elevate, not how or under what constraints. The actual JIT mechanics—such as approval requirements, activation time limits, justification fields, or MFA forcing—live entirely in the role settings. An eligible assignment combined with permissive role settings still leaves you with weak, uncontrolled activation, so eligible assignments alone do not implement JIT.

  • ✗

    Assignments (Active) for the Security Administrator role

    Why it's wrong here

    Active assignments provide continuous, standing access to the Security Administrator role without any activation step. Because the elevated permissions are always present, there is no elevation event where MFA, approval, or a time-bound window could be enforced, which directly defeats the goal of just-in-time access. To be JIT, users must be eligible rather than active, and the role settings must impose activation controls on top of that eligibility.

  • ✗

    Notifications settings under PIM

    Why it's wrong here

    Notifications settings under PIM govern email alerts for events like activation requests, approvals, role assignments, and elapsed-time warnings. These settings are purely informational and do not enforce or configure activation conditions—they only inform administrators about activity that has already occurred. While notifications complement a JIT strategy by improving monitoring and auditing, they are not the mechanism that implements JIT privileged access.

Go deeper

Related to this question

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.