MS-102 · Question #47
You have a Microsoft E5 subscription. You need to ensure that administrators who need to manage Microsoft Exchange Online are assigned the Exchange Administrator role for five hours at a time. What…
The correct answer is A. Azure AD Privileged Identity Management (PIM). Azure AD Privileged Identity Management (PIM) is purpose-built for time-bound and approval-gated role assignments. With PIM, you configure the Exchange Administrator role as 'eligible' for specific administrators. When they need access, they activate the role and the maximum…
Question
You have a Microsoft E5 subscription. You need to ensure that administrators who need to manage Microsoft Exchange Online are assigned the Exchange Administrator role for five hours at a time. What should you implement?
Options
- AAzure AD Privileged Identity Management (PIM)
- Ba conditional access policy
- Ca communication compliance policy
- DAzure AD Identity Protection
- Egroups that have dynamic membership
How the community answered
(21 responses)- A76% (16)
- B5% (1)
- C14% (3)
- D5% (1)
Explanation
Azure AD Privileged Identity Management (PIM) is purpose-built for time-bound and approval-gated role assignments. With PIM, you configure the Exchange Administrator role as 'eligible' for specific administrators. When they need access, they activate the role and the maximum activation duration can be set to exactly 5 hours - after which the role assignment automatically expires. This eliminates standing privileged access and reduces security risk. A Conditional Access policy controls access conditions but cannot automatically expire a role assignment after a set duration. Identity Protection, communication compliance, and dynamic groups do not provide time-bounded role assignment functionality.
Topics
Community Discussion
No community discussion yet for this question.