nerdexam
Microsoft

MS-102 · Question #332

You have a Microsoft 365 E5 subscription. You plan to configure Privileged Identity Management (PIM) for the User Administrator role in Microsoft Entra. You need to ensure that a user can make a…

The correct answer is A. Set Assignment type to Eligible. To allow a user to make a time-limited request for a role in Privileged Identity Management (PIM), the assignment type must be set to "Eligible" with a defined expiration.

Submitted by minji_kr· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

You have a Microsoft 365 E5 subscription. You plan to configure Privileged Identity Management (PIM) for the User Administrator role in Microsoft Entra. You need to ensure that a user can make a role assignment request for the User Administrator role only during the next six months. How should you configure the assignment?

Options

  • ASet Assignment type to Eligible.
  • BSet Assignment type to Active.
  • CSet Allow permanent active to assignment Yes.
  • DSet Allow permanent eligible assignment to Yes.

How the community answered

(35 responses)
  • A
    71% (25)
  • B
    3% (1)
  • C
    9% (3)
  • D
    17% (6)

Why each option

To allow a user to make a time-limited request for a role in Privileged Identity Management (PIM), the assignment type must be set to "Eligible" with a defined expiration.

ASet Assignment type to Eligible.Correct

Setting the Assignment type to "Eligible" in Privileged Identity Management (PIM) allows a user to request activation for a specific role when needed, rather than having permanent active access. For time-limited eligibility, such as for the next six months, the eligible assignment can be configured with an end date, ensuring the user can only make role assignment requests within that period and preventing permanent activation.

BSet Assignment type to Active.

Setting Assignment type to "Active" directly assigns the role to the user without requiring activation, and while it can be time-limited, it doesn't allow for making *requests* for the role, which is implied by the "only during the next six months" and "make a role assignment request" phrasing.

CSet Allow permanent active to assignment Yes.

Setting "Allow permanent active assignment to Yes" would enable permanent active role assignments, directly contradicting the requirement for a time-limited ability to make requests (next six months).

DSet Allow permanent eligible assignment to Yes.

Setting "Allow permanent eligible assignment to Yes" would allow eligible assignments to be permanent, which means the user could *always* request activation, contradicting the requirement that this ability is limited to the next six months.

Concept tested: PIM eligible assignments

Source: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-assign-azure-ad-roles#assign-an-azure-ad-role

Topics

#Privileged Identity Management (PIM)#Microsoft Entra ID#Role Assignments#Just-in-Time Access

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice