QuestionQ41

Secure identity and access

You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the users in the following table.

Question Image

Azure AD Privileged Identity Management (PIM) is used in contoso.com. In PIM, the Password Administrator role has these settings:

  • Maximum activation duration (hours): 2
  • Send email notifying admins of activation: Disable
  • Require incident/request ticket number during activation: Disable
  • Require Azure Multi-Factor Authentication for activation: Enable
  • Require approval to activate this role: Enable
  • Selected approver: Group1

You assign the Password Administrator role to users as shown in the following table.

Question Image

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Yes or No
StatementsYesNo
When User1 signs in, the user is assigned the Password Administrator role automatically.
User2 can request to activate the Password Administrator role.
If User3 wants to activate the Password Administrator role, the user can approve their own request.
Explanation

An Active PIM assignment makes the Password Administrator role active without an activation request. An Eligible assignment must be activated; because MFA is required for activation, a user whose MFA status is disabled cannot activate the role. Selected approvers cannot approve their own PIM role-activation requests, including when they are members of the approver group.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!