nerdexam
Microsoft

SC-300 · Question #36

Your company recently implemented Azure Active Directory (Azure AD) Privileged Identity Management (PIM). While you review the roles in PIM, you discover that all 15 users in the IT department at…

The correct answer is D. Assignment type to Eligible. "Assignment type to Eligible" so the admins can request the role in future, for a limited time based on the Role Setting of "Activation maximum duration (hours): 8 (by default)". https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-

Submitted by carlos_mx· Mar 6, 2026Implement Access Management for Apps and Infrastructure

Question

Your company recently implemented Azure Active Directory (Azure AD) Privileged Identity Management (PIM). While you review the roles in PIM, you discover that all 15 users in the IT department at the company have permanent security administrator rights. You need to ensure that the IT department users only have access to the Security administrator role when required. What should you configure for the Security administrator role assignment?

Options

  • AExpire eligible assignments after from the Role settings details
  • BExpire active assignments after from the Role settings details
  • CAssignment type to Active
  • DAssignment type to Eligible

How the community answered

(50 responses)
  • A
    8% (4)
  • B
    18% (9)
  • C
    4% (2)
  • D
    70% (35)

Explanation

"Assignment type to Eligible" so the admins can request the role in future, for a limited time based on the Role Setting of "Activation maximum duration (hours): 8 (by default)". https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-

Topics

#Privileged Identity Management#eligible assignments#PIM role configuration#Security administrator

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice