SC-300 - Plan and Automate Identity Governance (25% of the exam) - Section 4.4

Plan and manage privileged access using Microsoft Entra Privileged Identity Management for roles, resources, and groups.

Configure Privileged Identity Management for Microsoft Entra and Azure resource roles and for PIM for Groups, distinguishing eligible assignments from permanent active assignments. Define activation settings including maximum duration, justification, MFA, and approval so that privileged access is time-bound and auditable.

Privileged Identity Managementeligible and active assignmentsAzure resource roles in PIMPIM for Groupsactivation settings and approval

Practice question for this objective

Free samplePlan and Automate Identity Governancehard

An identity team must ensure that members of the Security Operations group hold no standing Security Administrator permissions but can raise themselves to that role for up to eight hours when they need to respond to an incident. Activation must require approval and multifactor authentication. Which Privileged Identity Management configuration meets the requirement with the least standing privilege?

  • ACreate an eligible Security Administrator assignment for each operator and set the role activation settings to a maximum eight-hour duration that requires approval and multifactor authentication. Correct
  • BCreate an active Security Administrator assignment for each operator and configure the role's activation settings to require approval and multifactor authentication for every action.
  • CAdd the operators to a group that holds a permanent Security Administrator assignment, then enable an access review so the group membership is recertified each quarter.
  • DCreate an eligible Security Administrator assignment for each operator but leave activation settings at their defaults so operators can elevate whenever an incident occurs.
Eligible PIM assignments grant no standing access until activation, and role activation settings enforce maximum duration, approval, and multifactor authentication requirements. Privileged Identity Management distinguishes the assignment type from the activation policy. An eligible assignment means the principal holds no permissions until they activate, while the role's activation settings control how long activation lasts and whether approval and multifactor authentication are demanded. Combining eligibility with an eight-hour, approval-gated, multifactor-protected activation policy satisfies just-in-time access at least privilege.

Why A is correct: An eligible assignment grants no standing access until the operator activates it, and role activation settings enforce the eight-hour cap, approval, and multifactor authentication, matching every part of the requirement.

Why B is wrong: An active assignment grants the role permanently and is not gated by activation, so the operator carries standing privilege at all times and the eight-hour, approval-based limit never applies.

Why C is wrong: A permanently assigned group still confers standing privilege between reviews, and an access review recertifies membership rather than enforcing just-in-time activation, approval, or a time limit on use.

Why D is wrong: Eligibility removes standing access, but default activation settings do not guarantee an approval step, multifactor authentication, or the specific eight-hour duration, so the stated controls are not enforced.

See more SC-300 practice questions, answers explained.

Exam traps in Plan and Automate Identity Governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-300 bank for this domain.

  • Assign the engineers an eligible Contributor assignment for the Microsoft Entra directory role, which automatically extends just-in-time control to every Azure subscription they can see.

    Why it is wrong: Contributor is an Azure resource role, not a Microsoft Entra directory role, and directory role eligibility never propagates to subscription scope, so this confuses the two distinct role planes.

  • Grant each engineer an eligible Microsoft Entra directory role, since Azure subscription Contributor access is governed through directory roles in Privileged Identity Management

    Why it is wrong: Contributor is an Azure resource role, not a Microsoft Entra directory role; the two role planes are managed separately in PIM, so a directory role cannot grant subscription access.

  • Grant the engineers the Contributor role directly through Azure role-based access control on the subscription so they hold the access permanently.

    Why it is wrong: A direct Azure RBAC assignment is standing access with no activation, approval, or PIM lifecycle, so it looks like the obvious way to grant Contributor yet it breaks the no-permanent-role requirement.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.