SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM). You need to design a role activation policy that requires approval from a security group for global administrator roles, but allows self-activation for other roles. What is the correct configuration?
⚠ Common exam trap
It's easy for candidates to confuse PIM role-specific policies with broader identity governance tools like entitlement management or Identity Protection, failing to recognize that PIM's granular per-role settings are the correct mechanism for mixed approval requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure separate PIM settings per role: Global Administrator requires approval, others self-activate
Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure role-specific activation settings. By creating separate PIM policies per role, you can require approval for the Global Administrator role while allowing self-activation for other roles. This granular control ensures that high-privilege roles have additional oversight, while lower-privilege roles remain agile.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a single PIM policy for all roles with approver group
Why it's wrong here
Creating a single PIM policy for all roles would apply identical activation requirements across every privileged role, forcing approval even for low-risk roles. PIM settings are role-specific, not global, so a unified policy would unjustifiably increase operational friction and violate the principle of least privilege. The correct approach is to tailor policies to each role's risk profile, not to reuse one blanket approver group.
- ✓
Configure separate PIM settings per role: Global Administrator requires approval, others self-activate
Why this is correct
This is correct because PIM supports granular, per-role configuration of activation settings, including whether approval is required. For Global Administrator, you can enable 'Require approval to activate' and assign a specific approver group, while leaving other roles configured for self-activation without approval. This balances security for highly sensitive roles with operational efficiency for lower-privilege roles, directly matching the requirement.
- ✗
Enable just-in-time access in Microsoft Entra ID Protection
Why it's wrong here
Enable just-in-time access in Microsoft Entra ID Protection is incorrect because Identity Protection is a risk-assessment service that detects anomalies such as leaked credentials, impossible travel, or risky sign-ins. It does not manage role activation, approval workflows, or session elevation for privileged identities. Just-in-time access is a core capability of Privileged Identity Management (PIM), not Identity Protection, so this option addresses a different problem entirely.
- ✗
Use Microsoft Entra ID entitlement management with access packages
Why it's wrong here
Microsoft Entra ID entitlement management is designed to create and manage access packages that bundle resources like groups, apps, and SharePoint sites for users, with approval and lifecycle policies. While it can grant temporary assignments, it does not provide PIM's role-specific activation workflow, such as activating a built-in directory role with justification and time-bound elevation. Entitlement management is unsuitable for managing privileged role activation; PIM is the dedicated service for that purpose.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.