nerdexam
Microsoft

SC-300 · Question #454

You have a Microsoft Entra tenant that contains three users named User1, User2, and User3. You need to configure just-in-time (JIT) access to admin roles by using Privileged Identity Management…

The correct answer is A. role assignments. To achieve your goal, first, create Privileged Access Groups (PAGs) for the User Administrator role, assign eligible members (User1, User2) to these groups, and then configure separate PIM Role Settings for each: one with no approval (automatic activation) for User1, and…

Submitted by krish.m· Mar 6, 2026Plan and implement identity governance

Question

You have a Microsoft Entra tenant that contains three users named User1, User2, and User3. You need to configure just-in-time (JIT) access to admin roles by using Privileged Identity Management (PIM). The solution must meet the following requirements:

  • Ensure that User1 can use the User Administrator role without

approval.

  • Ensure that User2 can use the User Administrator role once User3 has

approved the role request of User2. What should you create first?

Options

  • Arole assignments
  • Badministrative units
  • Csecurity groups
  • DConditional Access policies

How the community answered

(24 responses)
  • A
    79% (19)
  • B
    8% (2)
  • C
    8% (2)
  • D
    4% (1)

Explanation

To achieve your goal, first, create Privileged Access Groups (PAGs) for the User Administrator role, assign eligible members (User1, User2) to these groups, and then configure separate PIM Role Settings for each: one with no approval (automatic activation) for User1, and another with a custom approval workflow requiring User3's approval for User2. You'll create two separate PIM Role Assignments for the User Administrator role, one linked to each PAG, managing member settings to define activation requirements. Here's the step-by-step creation process: 1. Create Privileged Access Groups (PAGs) 2. Assign Users to Groups 3. Configure PIM Role Settings Go to Identity Governance > Privileged Identity Management > Microsoft Entra roles > Roles, then select the User Administrator role. For User (Auto Activation): *-> Select Add assignments, choose the PIM-UserAdmin-Auto group, set Assignment type to Eligible, and click Next. In Membership settings, select Edit. Set Activation settings to require MFA (recommended) but NO approval (or disable approval settings). For User2 (Approval Required): *-> Select Add assignments, choose the PIM-UserAdmin-Approval group, set Assignment type to Eligible, and click Next. In Membership settings, select Edit. Set Activation settings to require MFA and enable Require approval, specifying User 3 as the delegated approver. 4. Activate PIM for the User Administrator Role https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim- Exam Questions, Study Guides, Practice Tests. Lead the way to help you pass any IT Certification exams, 100% Pass Guaranteed or Full Refund. Especially Cisco, Microsoft, CompTIA, Citrix, EMC, HP, Oracle, VMware, Juniper, Check Point, LPI, Nortel, EXIN and so on. Our Slogan: First Test, First Pass. Help you to pass any IT Certification exams at the first try. You can reach us at any of the email addresses listed below. Any problems about IT certification or our products, you could rely upon us, we will give you satisfactory answers in 24 hours.

Topics

#Privileged Identity Management#just-in-time access#role assignments#approval workflow

Community Discussion

No community discussion yet for this question.

Full SC-300 Practice