MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
You are designing a Microsoft Entra ID governance strategy. Which THREE features should you use to implement the principle of least privilege for administrative roles?
⚠ Common exam trap
Candidates often confuse Entitlement Management (which handles access packages for end users) with Privileged Access Groups (which specifically control administrative role activation), leading them to select Option C instead of B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privileged Access Groups
Privileged Access Groups (B) enable you to grant just-in-time or time-bound access to Microsoft Entra ID roles and other resources by assigning users to a group that is eligible for role activation, directly supporting the principle of least privilege by limiting standing administrative access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Lifecycle Workflows
Why it's wrong here
Microsoft Entra Lifecycle Workflows automates joiner, mover, and leaver processes such as user provisioning, group membership updates, and access package assignments based on lifecycle events. However, they cannot assign or activate built-in or custom admin roles because they operate on user lifecycle state rather than privileged identity. Thus, they are unsuitable as the primary tool for governing administrative role access.
- ✓
Privileged Access Groups
Why this is correct
Privileged Access Groups (PAG) are role-assignable Microsoft Entra ID groups that can be mapped to Microsoft Entra ID roles, allowing group membership to control role eligibility. When PIM is enabled for these groups, admins receive just-in-time, time-bound activation, and dynamic membership rules can be used to add or remove users automatically based on attributes or lifecycle events. This combination makes PAG a modern, correct approach for admin role governance.
- ✗
Microsoft Entra Entitlement Management
Why it's wrong here
Microsoft Entra Entitlement Management governs access to business resources by creating access packages that bundle groups, applications, and SharePoint sites with approval workflows and assignment policies. It does not support built-in directory-level admin roles such as Global Administrator or Conditional Access Administrator, and it cannot enforce temporary, just-in-time activation of privileged roles. Therefore, it is not the correct choice for governing administrative role access.
- ✓
Microsoft Entra Privileged Identity Management (PIM)
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) provides just-in-time activation for Microsoft Entra ID roles and Azure resource roles, with capabilities such as approval workflows, multi-factor authentication, and time-bound session limits. It also includes audit logging, privileged role alerts, and can integrate with access reviews. While PIM is essential for controlling elevated access, it can also be combined with Privileged Access Groups for group-based role assignments rather than acting as an alternative.
- ✓
Microsoft Entra Access Reviews
Why this is correct
Microsoft Entra Access Reviews enables recurring recertification of group memberships and role assignments, helping to remove users who no longer need privileged access. However, they are primarily an attestation mechanism that runs periodically and does not provide just-in-time activation or time-bound role elevation. Access Reviews are a vital governance control but only become part of a complete strategy when used alongside PIM for dynamic privilege management.
Go deeper
Related to this question
Learn chapter
Privileged Access Management in M365
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.