nerdexam
Microsoft

AZ-104 · Question #388

Hotspot Question You have an Azure subscription named Subscription1. You enable Azure Active Directory (AD) Privileged Identity Management. From Azure AD Privileged Identity Management, you…

User2 will be active at 11:00 due to the 2-hour window, activation is not automatic because an MFA challenge must be completed interactively, and MFA is mandatorily enforced for the Global Administrator role.

Submitted by omar99· Mar 4, 2026Manage identities and governance

Question

Hotspot Question You have an Azure subscription named Subscription1. You enable Azure Active Directory (AD) Privileged Identity Management. From Azure AD Privileged Identity Management, you configure the Global Administrator role for the Azure Active Directory (Azure AD) tenant as shown in the Role settings exhibit. (Click the Exhibit tab.) From Azure AD Privileged Identity Management, you configure the global administrators as shown in the Members exhibit. (Click the Exhibit tab.) User2 activates the Global Administrator role on July 16, 2018, at 10:00, as shown in the Activation exhibit. (Click the Exhibit tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibits

AZ-104 question #388 exhibit 1
AZ-104 question #388 exhibit 2
AZ-104 question #388 exhibit 3
AZ-104 question #388 exhibit 4
AZ-104 question #388 exhibit 5
AZ-104 question #388 exhibit 6
AZ-104 question #388 exhibit 7
AZ-104 question #388 exhibit 8

Answer Area

  • Send email notifying admins of activation
  • Require incident/request ticket number during activation
  • Require Azure Multi-Factor Authentication for activation
  • Require approval to activate this role

Explanation

User2 will be active at 11:00 due to the 2-hour window, activation is not automatic because an MFA challenge must be completed interactively, and MFA is mandatorily enforced for the Global Administrator role.

Approach. Statement 1 is Yes: User2 activates the role at 10:00 AM and sets a custom duration of 2 hours. The activation ends at 12:00 PM. Therefore, at 11:00 AM, User2 holds the Global Administrator role.

Statement 2 is No: While admin approval is not required ('Require approval' is disabled), the process is not fully 'automatic'. When User2 attempts to activate the role, they are interrupted by a mandatory Multi-Factor Authentication (MFA) prompt. The request will not activate automatically in the background; it requires interactive user fulfillment of the MFA challenge.

Statement 3 is Yes: The Role settings exhibit clearly shows that 'Require Azure Multi-Factor Authentication for activation' is enabled. For the Global Administrator role, Microsoft enforces this setting by default to secure the tenant.

Common mistakes.

  • common_mistake. A common mistake is selecting 'Yes' for the second statement by assuming that because 'Require approval' is disabled, the role activates automatically without any friction. However, exam questions often distinguish between 'auto-approved' and 'activates automatically'; the mandatory MFA prompt makes the activation process interactive, not automatic.

Concept tested. Azure AD Privileged Identity Management (PIM) role settings, activation duration, and mandatory Multi-Factor Authentication (MFA) enforcement.

Reference. https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-activate-role

Topics

#Azure PIM#Azure AD Roles#PIM Role Activation#PIM Role Settings

Community Discussion

No community discussion yet for this question.

Full AZ-104 Practice