SC-300 · Question #221
Hotspot Question You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3. You have two Azure AD roles that have the Activation settings shown in the following
The correct answer is Role1 requires justification on activation. = No; Role1 requires approval to activate. = Yes; Role2 requires justification on activation. = Yes; Role2 requires approval to activate. = No. This question tests understanding of Azure AD Privileged Identity Management (PIM) role activation, approval workflows, and justification requirements based on different user actions and role configurations.
Question
Hotspot Question You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3. You have two Azure AD roles that have the Activation settings shown in the following table. The Azure AD roles have the Assignment settings shown in the following table. The Azure AD roles have the eligible users shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:
Exhibits
Answer Area
- Role1 requires justification on activation.No
- Role1 requires approval to activate.Yes
- Role2 requires justification on activation.Yes
- Role2 requires approval to activate.No
Explanation
This question tests understanding of Azure AD Privileged Identity Management (PIM) role activation, approval workflows, and justification requirements based on different user actions and role configurations.
Approach. To answer correctly, each statement must be evaluated against the provided PIM configuration tables, keeping in mind Azure PIM's operational principles.
Statement 1: If User1 requests Role1, the request will be approved automatically.
- Correct Interaction: Select 'No'.
- Reasoning: According to the 'Activation settings' table, Role1 requires approval to activate ('Require approval to activate: Yes'), and User1 is listed as the approver. However, a fundamental security principle in Azure AD PIM is that a user cannot approve their own request for role activation. If User1 requests Role1, and User1 is the only designated approver, the request cannot be approved by User1 and therefore will not be 'automatically approved'. It would typically remain in a pending state or fail if no alternative approver is configured.
Statement 2: User1 can approve the request of User3 for Role2.
- Correct Interaction: Select 'No'.
- Reasoning: Referring to the 'Activation settings' table for Role2, the 'Require approval to activate' setting is 'No'. This means that requests for Role2 activation do not go through an approval workflow. They are automatically activated (assuming any required justification from the requestor is provided). Since no approval is necessary, User1 has no role to play in approving User3's request for Role2.
Statement 3: User1 must provide justification to approve the request of User2 for Role1.
- Correct Interaction: Select 'Yes'.
- Reasoning: In this scenario, User1 is acting as an approver for User2's request to activate Role1. The 'Assignment settings' table for Role1 shows 'Require justification on active assignment: Yes'. This setting specifically applies to the approver, meaning that when an approver processes an active assignment (which includes approving an activation request), they must provide a justification for that approval. Therefore, User1 must provide justification.
Common mistakes.
- common_mistake. 1. For Statement 1 ('If User1 requests Role1, the request will be approved automatically.'): A common mistake is to assume that because User1 is listed as the approver for Role1, their own request would be automatically approved or bypass the approval process. This is incorrect. Azure PIM explicitly prevents users from approving their own requests to uphold security best practices. If a self-approver is designated, the request typically requires another approver or becomes unapprovable.
- For Statement 2 ('User1 can approve the request of User3 for Role2.'): Misinterpreting the 'Require approval to activate: No' setting is a common error. Some might think that 'None' in the 'Approvers' column means User1 could approve if they had the right permissions, or confuse it with a scenario where no approver is assigned but approval is still technically required. However, 'No' explicitly means the approval step is skipped entirely, making any approval action impossible.
- For Statement 3 ('User1 must provide justification to approve the request of User2 for Role1.'): A frequent mistake is to confuse the 'Required justification on activation' (which applies to the user requesting the role) with 'Require justification on active assignment' (which applies to the approver of the assignment/activation). The tables clearly separate these two types of justification, and ignoring this distinction would lead to an incorrect answer.
Concept tested. The core technical concept being tested is Azure AD Privileged Identity Management (PIM) and its granular controls over role activation workflows. This includes:
- Understanding of PIM activation settings (justification for requestor, approval requirement, designated approvers).
- Understanding of PIM assignment settings (justification for approver on active assignment).
- The security principle that users cannot approve their own PIM role activation requests.
- Differentiating between justification required from the requestor vs. the approver.
- Interpreting 'Require approval to activate: No' as an automatic activation process (assuming requestor justification is met).
Topics
Community Discussion
No community discussion yet for this question.

