Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

You are a Microsoft 365 administrator for a company that uses Microsoft Entra ID P2. The company has a requirement that all administrative roles must be activated only after approval by a designated approver. You configure Privileged Identity Management (PIM) for the Global Administrator role. You need to ensure that when a user activates the role, an approver must approve the request before the role is activated. What should you configure in the PIM role settings?

⚠ Common exam trap

A common mix-up: candidates confuse MFA on activation with approval on activation; MFA verifies the user's identity but does not require a second person's approval.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable 'Require approval to activate' and specify the approvers.

The 'Require approval to activate' setting in PIM role settings enforces an approval workflow. When a user requests activation, the designated approvers receive a notification and must approve the request before the role is activated. This ensures that administrative roles are activated only after explicit approval, meeting the company's requirement. It is configured per role in PIM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'Require multifactor authentication on activation'.

    Why it's wrong here

    Requiring MFA on activation adds an authentication factor during activation, but it does not require a separate approver. The user can activate the role without any approval, as long as they satisfy MFA. This does not meet the approval requirement.

  • ✓

    Enable 'Require approval to activate' and specify the approvers.

    Why this is correct

    In PIM role settings, the 'Require approval to activate' option enforces that a designated approver must approve an activation request. You can specify one or more approvers. This directly meets the requirement that administrative roles must be activated only after approval by a designated approver.

  • ✗

    Set Activation maximum duration to 1 hour.

    Why it's wrong here

    Activation maximum duration controls how long the role remains active after activation. It does not enforce approval. Setting a short duration reduces the window of privilege but does not require an approver to authorize the activation. This setting alone does not meet the requirement.

  • ✗

    Configure 'Require justification on activation'.

    Why it's wrong here

    Requiring justification prompts the user to enter a reason for activation, but it does not enforce approval by another person. The activation proceeds after justification is provided. This is a logging and auditing feature, not an approval workflow.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.