MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Which TWO Microsoft Entra ID features can be used to provide just-in-time (JIT) access to privileged roles?
⚠ Common exam trap
Many exam-takers confuse Access Reviews (a recertification tool) with JIT activation, or think Conditional Access can provide time-bound role elevation when it only controls access to apps, not role assignments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Identity Management (PIM)
Privileged Identity Management (PIM) provides just-in-time (JIT) access by allowing users to activate eligible role assignments for a limited time, with approval workflows and auditing. Privileged Access Groups extend JIT capabilities by enabling time-bound membership in groups that grant access to Microsoft Entra ID roles or Azure resources, ensuring temporary elevation only when needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identity Protection
Why it's wrong here
Microsoft Entra ID Protection is designed to detect and remediate identity-based risks such as impossible travel, leaked credentials, and risky sign-in behavior. It does not grant or activate privileged roles; it can trigger Conditional Access to require MFA or password reset, but it cannot provide temporary privilege elevation. Therefore, it is not the mechanism for just-in-time role activation.
- ✓
Privileged Identity Management (PIM)
Why this is correct
Privileged Identity Management (PIM) is the primary Microsoft Entra ID service for just-in-time (JIT) access, enabling users to activate eligible role assignments for a limited time with justification and optional approval. During activation, the role is temporarily added to the user's list of active assignments, and after the maximum duration (for example, 8 hours) it automatically expires. PIM also provides audit history and alerts for activations, making it the correct answer for time-bound role elevation.
- ✗
Conditional Access
Why it's wrong here
Conditional Access policies in Microsoft Entra ID evaluate signals like user, device compliance, location, and risk level to enforce access control decisions on applications. While a policy can gate app access with MFA or blocking, it cannot grant a Microsoft Entra directory role or elevate a user's permissions. It is a policy engine for session and app access, not an activation mechanism for privileged roles, so it does not produce just-in-time role activation.
- ✗
Access Reviews
Why it's wrong here
Access Reviews in Microsoft Entra ID are used for continuously auditing and certifying that existing role or group assignments are still appropriate, typically on a recurring schedule. They allow responsible parties to approve or remove access, but they do not create temporary assignments or provide a way for a user to activate a role on demand. Thus, they serve as a governance control after access is granted, not as the just-in-time elevation mechanism.
- ✓
Privileged Access Groups
Why this is correct
Privileged Access Groups in Microsoft Entra ID extend PIM to assign users as eligible members or owners of groups that have been granted permissions, including roles. With these groups, an admin can use group assignments as a vehicle for JIT membership, allowing members to actively activate their group membership for a limited time. Because the group itself can be assigned to an Entra ID role, this provides a valid just-in-time path, though it is essentially PIM for groups.
Go deeper
Related to this question
Learn chapter
Azure Active Directory Domain Services (AADDS)
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Privileged Identity Management
Privileged Identity Management is a security system that controls, monitors, and audits access to sensitive systems by granting elevated permissions only when needed and for a limited time.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.