MS-102 Practice Question: Implement and manage Microsoft Entra identity and access
Your company uses Microsoft Entra ID. You need to ensure that when users are assigned privileged roles, they must activate the role and provide a justification. The solution must minimize the number of standing assignments. What should you implement?
⚠ Common exam trap
The trap here is assuming that Conditional Access or access reviews can enforce just-in-time role activation with justification, which they cannot.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Privileged Identity Management (PIM) with eligible assignments and activation requirements.
Microsoft Entra Privileged Identity Management (PIM) provides just-in-time privileged access. By configuring eligible assignments, users must activate roles when needed, and you can require justification and MFA. This minimizes standing access. Other options do not provide activation workflows or justification requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditional Access policy requiring MFA for all users assigned to privileged roles.
Why it's wrong here
Conditional Access can require MFA for privileged users, but it does not enforce activation with justification or minimize standing assignments. Users would still have permanent role assignments. This does not meet the requirement for just-in-time access with justification.
- ✗
Microsoft Entra ID Protection risk policies for privileged users.
Why it's wrong here
Risk policies detect and respond to risky sign-ins or users, but they do not manage role activation or justification. They are not designed to minimize standing privileged assignments. This does not fulfill the requirement for just-in-time privileged access.
- ✓
Microsoft Entra Privileged Identity Management (PIM) with eligible assignments and activation requirements.
Why this is correct
PIM allows you to assign users as eligible for privileged roles. When they need the role, they must activate it, optionally providing justification and passing MFA. This minimizes standing access and meets the requirement. It is the correct solution for just-in-time privileged access.
- ✗
Microsoft Entra ID Governance access reviews for privileged roles.
Why it's wrong here
Access reviews help ensure that users still need their roles, but they do not enforce activation with justification at the time of use. They also do not minimize standing assignments; users retain roles until a review removes them. This does not provide just-in-time access.
Go deeper
Related to this question
Learn chapter
Teams Channels and External Access Governance
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.