Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Entra ID for identity management and wants to implement a least-privilege access model for administrators. You need to reduce standing privileges and ensure that admin roles are activated only when needed with approval workflow. Requirements: (1) Require approval for activation of Global Administrator role, (2) Set activation duration to 4 hours maximum, (3) Require Azure MFA for activation, (4) Receive notifications when roles are activated, (5) Audit all activations for compliance. Which Microsoft Entra ID capability should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privileged Identity Management (PIM)

Microsoft Entra Privileged Identity Management (PIM) is the correct choice because it provides just-in-time role activation with configurable approval workflows, maximum activation duration, MFA enforcement, activation notifications, and audit history for privileged roles like Global Administrator. In PIM, you can set the Global Administrator role as eligible, require approval, cap activation at 4 hours, require Azure MFA, and enable notifications and auditing, which directly satisfies all five requirements. Access Reviews (A) only handles periodic attestation of group or role membership and cannot enforce activation approval, duration, or MFA. Identity Protection (C) detects risky sign-ins and users but does not manage privileged role activation workflows. Conditional Access (D) can enforce MFA and other access controls at sign-in, but it does not provide role activation approval, time-bound activation, or activation audit trails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Access Reviews

    Why it's wrong here

    Access Reviews in Microsoft Entra ID are designed to recertify existing group memberships, application roles, and Entra role assignments at defined intervals. They generate attestation tasks for owners or reviewers, but they do not manage the activation process for a role, nor do they enforce time-bound elevation, approval workflows, or MFA at the moment of activation. Thus, while Access Reviews can complement a PIM implementation by auditing who still needs privileged access, they are not a workflow engine for on-demand role activation.

  • ✓

    Privileged Identity Management (PIM)

    Why this is correct

    Privileged Identity Management (PIM) in Microsoft Entra ID is the service that provides just-in-time (JIT) privileged role activation. PIM allows an eligible user to activate a role for a limited time, optionally requiring approval, multi-factor authentication (MFA), and justification, and it records the activation in the audit log. This directly matches the requirement to create a workflow for role activation that includes human approval, thereby making PIM the correct answer for controlling privileged access activation.

  • ✗

    Identity Protection

    Why it's wrong here

    Microsoft Entra Identity Protection is a risk-detection service that evaluates sign-in and user risk signals, such as impossible travel, leaked credentials, and anonymous IP addresses, and then applies conditional access policies to block or require remediation. It does not manage the assignment or activation of Entra roles, nor does it provide approval workflows for granting privileges. Its purpose is to detect compromised identities and mitigate authentication risks, not to govern role activation.

  • ✗

    Conditional Access

    Why it's wrong here

    Conditional Access in Microsoft Entra ID is a policy engine that enforces access controls, such as MFA or device compliance, at the time of authentication or session initiation. It can be used to gate token issuance for applications, but it cannot activate an Entra role or run an approval-based workflow for role elevation. Conditional Access could be integrated as a security control during the PIM activation flow, but by itself it lacks the role-management and approval lifecycle capabilities required by this scenario.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.