Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Which TWO Microsoft Entra ID features can be used to provide just-in-time (JIT) access to privileged roles?

⚠ Common exam trap

Many exam-takers confuse Access Reviews (a recertification tool) with JIT activation, or think Conditional Access can provide time-bound role elevation when it only controls access to apps, not role assignments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged Identity Management (PIM)

Privileged Identity Management (PIM) provides just-in-time (JIT) access by allowing users to activate eligible role assignments for a limited time, with approval workflows and auditing. Privileged Access Groups extend JIT capabilities by enabling time-bound membership in groups that grant access to Microsoft Entra ID roles or Azure resources, ensuring temporary elevation only when needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identity Protection

    Why it's wrong here

    Microsoft Entra ID Protection is designed to detect and remediate identity-based risks such as impossible travel, leaked credentials, and risky sign-in behavior. It does not grant or activate privileged roles; it can trigger Conditional Access to require MFA or password reset, but it cannot provide temporary privilege elevation. Therefore, it is not the mechanism for just-in-time role activation.

  • ✓

    Privileged Identity Management (PIM)

    Why this is correct

    Privileged Identity Management (PIM) is the primary Microsoft Entra ID service for just-in-time (JIT) access, enabling users to activate eligible role assignments for a limited time with justification and optional approval. During activation, the role is temporarily added to the user's list of active assignments, and after the maximum duration (for example, 8 hours) it automatically expires. PIM also provides audit history and alerts for activations, making it the correct answer for time-bound role elevation.

  • ✗

    Conditional Access

    Why it's wrong here

    Conditional Access policies in Microsoft Entra ID evaluate signals like user, device compliance, location, and risk level to enforce access control decisions on applications. While a policy can gate app access with MFA or blocking, it cannot grant a Microsoft Entra directory role or elevate a user's permissions. It is a policy engine for session and app access, not an activation mechanism for privileged roles, so it does not produce just-in-time role activation.

  • ✗

    Access Reviews

    Why it's wrong here

    Access Reviews in Microsoft Entra ID are used for continuously auditing and certifying that existing role or group assignments are still appropriate, typically on a recurring schedule. They allow responsible parties to approve or remove access, but they do not create temporary assignments or provide a way for a user to activate a role on demand. Thus, they serve as a governance control after access is granted, not as the just-in-time elevation mechanism.

  • ✓

    Privileged Access Groups

    Why this is correct

    Privileged Access Groups in Microsoft Entra ID extend PIM to assign users as eligible members or owners of groups that have been granted permissions, including roles. With these groups, an admin can use group assignments as a vehicle for JIT membership, allowing members to actively activate their group membership for a limited time. Because the group itself can be assigned to an Entra ID role, this provides a valid just-in-time path, though it is essentially PIM for groups.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.