MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
You are the identity administrator for a Microsoft 365 E5 tenant. The company uses Microsoft Entra ID P2. The security team wants to implement just-in-time role activation for the 'Security Administrator' role. They want to ensure that when a user activates the role, they must provide a justification and approve via multi-factor authentication. They also want the activation to last for a maximum of 4 hours. You configure Privileged Identity Management (PIM). Which setting should you configure to meet the requirement for justification and MFA?
⚠ Common exam trap
Many exam-takers confuse PIM activation requirements with Conditional Access MFA, which does not provide justification or just-in-time activation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the role settings, enable 'Require justification on activation' and 'Require Microsoft Entra multifactor authentication on activation'.
In PIM, role settings include options to require justification and Microsoft Entra multifactor authentication on activation. Enabling both ensures that when a user activates the Security Administrator role, they must provide a reason and complete MFA. The maximum activation duration is set separately in the same role settings. This configuration satisfies the just-in-time access requirements with the specified controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the role as eligible and set the maximum activation duration to 4 hours.
Why it's wrong here
Setting the role as eligible and limiting duration is necessary for just-in-time access, but it does not enforce justification or MFA during activation. The question asks specifically for the setting to meet justification and MFA. This option only addresses the duration aspect, so it is incomplete.
- ✓
In the role settings, enable 'Require justification on activation' and 'Require Microsoft Entra multifactor authentication on activation'.
Why this is correct
These settings are part of the role settings in PIM. Enabling 'Require justification on activation' forces users to provide a reason when activating. Enabling 'Require Microsoft Entra multifactor authentication on activation' enforces MFA during activation. Together, they meet the requirement for justification and MFA, and the maximum activation duration can be set separately.
- ✗
Configure a Conditional Access policy that requires MFA for the Security Administrator role.
Why it's wrong here
Conditional Access can require MFA for users with privileged roles, but it does not provide just-in-time activation or justification. It also does not limit activation duration. The requirement specifically mentions PIM activation with justification and MFA, so Conditional Access alone is insufficient and does not address the activation workflow.
- ✗
In the role settings, enable 'Require approval to activate' and specify approvers.
Why it's wrong here
Requiring approval adds an approval step but does not enforce MFA or justification. The requirement asks for justification and MFA, not approval. While approval can be part of PIM, it is a separate control and would not satisfy the MFA requirement. Thus, this setting alone does not meet the needs.
Go deeper
Related to this question
Learn chapter
Tenant-Wide Settings and Org Profile
Key term
Just-in-time access
Just-in-time access is a security method that grants users elevated permissions only for a limited time exactly when they need them, then automatically removes those permissions.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.