Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Entra ID with Privileged Identity Management (PIM). You need to design a role activation policy that requires approval from a security group for global administrator roles, but allows self-activation for other roles. What is the correct configuration?

⚠ Common exam trap

It's easy for candidates to confuse PIM role-specific policies with broader identity governance tools like entitlement management or Identity Protection, failing to recognize that PIM's granular per-role settings are the correct mechanism for mixed approval requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure separate PIM settings per role: Global Administrator requires approval, others self-activate

Privileged Identity Management (PIM) in Microsoft Entra ID allows you to configure role-specific activation settings. By creating separate PIM policies per role, you can require approval for the Global Administrator role while allowing self-activation for other roles. This granular control ensures that high-privilege roles have additional oversight, while lower-privilege roles remain agile.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a single PIM policy for all roles with approver group

    Why it's wrong here

    Creating a single PIM policy for all roles would apply identical activation requirements across every privileged role, forcing approval even for low-risk roles. PIM settings are role-specific, not global, so a unified policy would unjustifiably increase operational friction and violate the principle of least privilege. The correct approach is to tailor policies to each role's risk profile, not to reuse one blanket approver group.

  • ✓

    Configure separate PIM settings per role: Global Administrator requires approval, others self-activate

    Why this is correct

    This is correct because PIM supports granular, per-role configuration of activation settings, including whether approval is required. For Global Administrator, you can enable 'Require approval to activate' and assign a specific approver group, while leaving other roles configured for self-activation without approval. This balances security for highly sensitive roles with operational efficiency for lower-privilege roles, directly matching the requirement.

  • ✗

    Enable just-in-time access in Microsoft Entra ID Protection

    Why it's wrong here

    Enable just-in-time access in Microsoft Entra ID Protection is incorrect because Identity Protection is a risk-assessment service that detects anomalies such as leaked credentials, impossible travel, or risky sign-ins. It does not manage role activation, approval workflows, or session elevation for privileged identities. Just-in-time access is a core capability of Privileged Identity Management (PIM), not Identity Protection, so this option addresses a different problem entirely.

  • ✗

    Use Microsoft Entra ID entitlement management with access packages

    Why it's wrong here

    Microsoft Entra ID entitlement management is designed to create and manage access packages that bundle resources like groups, apps, and SharePoint sites for users, with approval and lifecycle policies. While it can grant temporary assignments, it does not provide PIM's role-specific activation workflow, such as activating a built-in directory role with justification and time-bound elevation. Entitlement management is unsuitable for managing privileged role activation; PIM is the dedicated service for that purpose.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.