MS-102 · Question #332
You have a Microsoft 365 E5 subscription. You plan to configure Privileged Identity Management (PIM) for the User Administrator role in Microsoft Entra. You need to ensure that a user can make a…
The correct answer is A. Set Assignment type to Eligible. To allow a user to make a time-limited request for a role in Privileged Identity Management (PIM), the assignment type must be set to "Eligible" with a defined expiration.
Question
You have a Microsoft 365 E5 subscription. You plan to configure Privileged Identity Management (PIM) for the User Administrator role in Microsoft Entra. You need to ensure that a user can make a role assignment request for the User Administrator role only during the next six months. How should you configure the assignment?
Options
- ASet Assignment type to Eligible.
- BSet Assignment type to Active.
- CSet Allow permanent active to assignment Yes.
- DSet Allow permanent eligible assignment to Yes.
How the community answered
(35 responses)- A71% (25)
- B3% (1)
- C9% (3)
- D17% (6)
Why each option
To allow a user to make a time-limited request for a role in Privileged Identity Management (PIM), the assignment type must be set to "Eligible" with a defined expiration.
Setting the Assignment type to "Eligible" in Privileged Identity Management (PIM) allows a user to request activation for a specific role when needed, rather than having permanent active access. For time-limited eligibility, such as for the next six months, the eligible assignment can be configured with an end date, ensuring the user can only make role assignment requests within that period and preventing permanent activation.
Setting Assignment type to "Active" directly assigns the role to the user without requiring activation, and while it can be time-limited, it doesn't allow for making *requests* for the role, which is implied by the "only during the next six months" and "make a role assignment request" phrasing.
Setting "Allow permanent active assignment to Yes" would enable permanent active role assignments, directly contradicting the requirement for a time-limited ability to make requests (next six months).
Setting "Allow permanent eligible assignment to Yes" would allow eligible assignments to be permanent, which means the user could *always* request activation, contradicting the requirement that this ability is limited to the next six months.
Concept tested: PIM eligible assignments
Source: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-assign-azure-ad-roles#assign-an-azure-ad-role
Topics
Community Discussion
No community discussion yet for this question.