nerdexam
Microsoft

MS-102 · Question #46

You have a Microsoft 365 subscription that contains a user named User1. User1 requires admin access to perform the following tasks: - Manage Microsoft Exchange Online settings. - Create Microsoft…

The correct answer is D. Azure AD Privileged Identity Management (PIM). To provide User1 with time-bound administrative access requiring approval for managing Exchange Online and creating Microsoft 365 groups, Azure AD Privileged Identity Management (PIM) is the correct tool.

Submitted by ravi_2018· Apr 18, 2026Implement and manage Microsoft Entra identity and access

Question

You have a Microsoft 365 subscription that contains a user named User1. User1 requires admin access to perform the following tasks:

  • Manage Microsoft Exchange Online settings.
  • Create Microsoft 365 groups.

You need to ensure that User1 only has admin access for eight hours and requires approval before the role assignment takes place. What should you use?

Options

  • AAzure AD Identity Protection
  • BMicrosoft Entra Verified ID
  • CConditional Access
  • DAzure AD Privileged Identity Management (PIM)

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    14% (4)
  • C
    4% (1)
  • D
    75% (21)

Why each option

To provide User1 with time-bound administrative access requiring approval for managing Exchange Online and creating Microsoft 365 groups, Azure AD Privileged Identity Management (PIM) is the correct tool.

AAzure AD Identity Protection

Azure AD Identity Protection focuses on detecting and remediating identity-based risks, such as compromised accounts, not on managing time-bound access or approval workflows for administrative roles.

BMicrosoft Entra Verified ID

Microsoft Entra Verified ID is a decentralized identity solution for verifiable credentials and does not relate to managing time-bound administrative access or approval workflows within an organization's Azure AD tenant.

CConditional Access

Conditional Access policies control access to resources based on conditions (e.g., location, device compliance) but do not provide just-in-time role activation with approval workflows for administrative roles.

DAzure AD Privileged Identity Management (PIM)Correct

Azure AD Privileged Identity Management (PIM) allows for just-in-time (JIT) access to administrative roles, time-bound assignments, and includes approval workflows for role activation, which directly meets the requirements for temporary, approved admin access for User1.

Concept tested: Azure AD Privileged Identity Management (PIM)

Source: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure

Topics

#Privileged Identity Management#Just-in-Time access#Role assignment approval#Microsoft Entra ID

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice