Your organization uses Microsoft Entra ID with P2 licenses. You need to delegate the ability to manage role assignments in Entra ID without granting global admin rights. Which feature should you use?
Microsoft Entra Privileged Identity Management (PIM) is the correct solution for managing, controlling, and monitoring access to important resources within Microsoft Entra ID and other Microsoft online services. PIM specifically enables just-in-time (JIT) access to roles, time-bound assignments, and approval workflows for role activation. It allows organizations to delegate the management of role assignments, including the ability for designated users to assign eligible roles to others, thereby significantly reducing the standing access of highly privileged accounts.
Why this answer
Privileged Identity Management (PIM) in Microsoft Entra ID P2 enables just-in-time, time-bound, and approval-based role assignments, allowing you to delegate role management without granting permanent global admin rights. PIM provides role activation workflows and auditing, making it the correct feature for delegating role assignment management.
Exam trap
The trap here is confusing Administrative Units (which limit scope) with Privileged Identity Management (which manages role assignment delegation and activation), as both deal with role management but serve different purposes.
How to eliminate wrong answers
Option A is wrong because Entitlement Management is for managing access packages and resource access lifecycle, not for delegating role assignments in Entra ID. Option B is wrong because Conditional Access enforces access policies based on signals like user location or device compliance, but does not delegate role management. Option C is wrong because Administrative Units restrict administrative scope to specific organizational units (e.g., departments) but do not delegate the ability to manage role assignments themselves; they limit where a role applies, not who can assign roles.