Courseiva

MS-102 Practice Question: Implement and manage Microsoft Entra identity and access

Your organization has a Microsoft 365 E5 subscription and uses Microsoft Entra ID. You are implementing Privileged Identity Management (PIM) to manage access to Microsoft Entra ID roles. You need to ensure that when a user activates a privileged role, the activation request must be approved by their manager and must include a ticket number. What should you configure?

⚠ Common exam trap

Candidates often confuse Entitlement Management access packages (which also support approval workflows) with PIM role settings, but only PIM role settings allow you to require a ticket number and specify the manager as the approver for Microsoft Entra ID role activation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the role settings in PIM to require approval and justification with ticket number

PIM role settings allow you to configure activation requirements, including requiring approval and mandating a justification field. By enabling 'Require approval to activate' and configuring the approver as the user's manager, and by setting 'Require ticket information on activation', you enforce that every activation request includes a ticket number and is routed to the manager for approval.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an access review for the role

    Why it's wrong here

    Creating an access review for the privileged role would periodically recertify whether existing members should retain standing access, but it does not intercept or govern the moment a user activates the role. The requirement is to enforce approval and a ticket number during activation, which is handled by PIM role settings rather than by a scheduled review. Access reviews happen on a cadence, not at activation time, so this option cannot satisfy the stated control.

  • ✓

    Modify the role settings in PIM to require approval and justification with ticket number

    Why this is correct

    In Privileged Identity Management (PIM), you can modify the role's settings to require approval for activation and mandate that the user supply a justification, which can include the support ticket number before the role becomes active. This enforcement is embedded directly in the activation workflow, so the request is routed to designated approvers and the ticket reference is captured. Because the scenario asks for exactly this type of activation-time control, changing the PIM role settings is the correct solution.

  • ✗

    Configure an access package in Entitlement Management

    Why it's wrong here

    An access package in Entitlement Management governs requests for access to resources such as groups, applications, and SharePoint sites, with policies that control who can request and approve resource assignments. Although an access package can include directory roles, it is not the mechanism for enforcing PIM role activation approvals or collecting ticket-number justification during a privileged role activation. Entitlement Management is a separate access-governance tool, so it neither replaces nor modifies PIM's role activation settings and therefore does not meet the requirement.

  • ✗

    Use Conditional Access policy with session controls

    Why it's wrong here

    Conditional Access policies evaluate sign-in conditions like user risk, device compliance, location, and application, then apply controls such as multifactor authentication or session restrictions; they do not manage the PIM role activation lifecycle. Session controls cannot require an approver to review a role activation request or force the user to enter a ticket number before elevation. Since the requirement is about privileged role activation approval in PIM, Conditional Access is an unrelated control plane and cannot achieve this outcome.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.