Your company uses Microsoft Entra ID with P2 licenses. You want to require approval for users to activate the Global Administrator role. Which feature should you configure?
Microsoft Entra Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to important resources by providing just-in-time (JIT) and just-enough-access (JEA) to privileged roles. It enables approval workflows for role activation, requiring users to request elevation and obtain approval before gaining temporary administrative rights. This directly addresses the need for a controlled and auditable process for activating privileged roles.
Why this answer
Privileged Identity Management (PIM) in Microsoft Entra ID P2 provides just-in-time privileged access, including the ability to require approval for role activation. By configuring PIM for the Global Administrator role, you can enforce that users must request activation and receive approval before gaining the role's permissions, ensuring least-privilege and auditability.
Exam trap
The trap here is that candidates often confuse Conditional Access (which controls sign-in conditions) with PIM's approval workflow, but Conditional Access cannot enforce a multi-step approval process for role activation; only PIM provides that capability.
How to eliminate wrong answers
Option B (Identity Protection) is wrong because it focuses on detecting and responding to identity risks (e.g., compromised accounts, risky sign-ins) and does not manage role activation workflows or approval requirements. Option C (Conditional Access) is wrong because it enforces access policies based on conditions like location or device state, but it does not provide approval-based role activation; it controls sign-in access, not role elevation. Option D (Access reviews) is wrong because it periodically recertifies existing role assignments, ensuring they are still needed, but it does not enforce an approval step for activating a role in real time.