Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

You are designing a Microsoft Entra ID governance strategy. Which THREE features should you use to implement the principle of least privilege for administrative roles?

⚠ Common exam trap

Candidates often confuse Entitlement Management (which handles access packages for end users) with Privileged Access Groups (which specifically control administrative role activation), leading them to select Option C instead of B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged Access Groups

Privileged Access Groups (B) enable you to grant just-in-time or time-bound access to Microsoft Entra ID roles and other resources by assigning users to a group that is eligible for role activation, directly supporting the principle of least privilege by limiting standing administrative access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra Lifecycle Workflows

    Why it's wrong here

    Microsoft Entra Lifecycle Workflows automates joiner, mover, and leaver processes such as user provisioning, group membership updates, and access package assignments based on lifecycle events. However, they cannot assign or activate built-in or custom admin roles because they operate on user lifecycle state rather than privileged identity. Thus, they are unsuitable as the primary tool for governing administrative role access.

  • ✓

    Privileged Access Groups

    Why this is correct

    Privileged Access Groups (PAG) are role-assignable Microsoft Entra ID groups that can be mapped to Microsoft Entra ID roles, allowing group membership to control role eligibility. When PIM is enabled for these groups, admins receive just-in-time, time-bound activation, and dynamic membership rules can be used to add or remove users automatically based on attributes or lifecycle events. This combination makes PAG a modern, correct approach for admin role governance.

  • ✗

    Microsoft Entra Entitlement Management

    Why it's wrong here

    Microsoft Entra Entitlement Management governs access to business resources by creating access packages that bundle groups, applications, and SharePoint sites with approval workflows and assignment policies. It does not support built-in directory-level admin roles such as Global Administrator or Conditional Access Administrator, and it cannot enforce temporary, just-in-time activation of privileged roles. Therefore, it is not the correct choice for governing administrative role access.

  • ✓

    Microsoft Entra Privileged Identity Management (PIM)

    Why this is correct

    Microsoft Entra Privileged Identity Management (PIM) provides just-in-time activation for Microsoft Entra ID roles and Azure resource roles, with capabilities such as approval workflows, multi-factor authentication, and time-bound session limits. It also includes audit logging, privileged role alerts, and can integrate with access reviews. While PIM is essential for controlling elevated access, it can also be combined with Privileged Access Groups for group-based role assignments rather than acting as an alternative.

  • ✓

    Microsoft Entra Access Reviews

    Why this is correct

    Microsoft Entra Access Reviews enables recurring recertification of group memberships and role assignments, helping to remove users who no longer need privileged access. However, they are primarily an attestation mechanism that runs periodically and does not provide just-in-time activation or time-bound role elevation. Access Reviews are a vital governance control but only become part of a complete strategy when used alongside PIM for dynamic privilege management.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.