SC-300 - Plan and Automate Identity Governance - Section 4.4

Plan and manage privileged access using Microsoft Entra Privileged Identity Management for roles, resources, and groups.

Configure Privileged Identity Management for Microsoft Entra and Azure resource roles and for PIM for Groups, distinguishing eligible assignments from permanent active assignments. Define activation settings including maximum duration, justification, MFA, and approval so that privileged access is time-bound and auditable.

Privileged Identity Managementeligible and active assignmentsAzure resource roles in PIMPIM for Groupsactivation settings and approval

Practice question for this objective

Free samplePlan and Automate Identity Governancehard

An identity team must ensure that members of the Security Operations group hold no standing Security Administrator permissions but can raise themselves to that role for up to eight hours when they need to respond to an incident. Activation must require approval and multifactor authentication. Which Privileged Identity Management configuration meets the requirement with the least standing privilege?

  • ACreate an eligible Security Administrator assignment for each operator and set the role activation settings to a maximum eight-hour duration that requires approval and multifactor authentication. Correct
  • BCreate an active Security Administrator assignment for each operator and configure the role's activation settings to require approval and multifactor authentication for every action.
  • CAdd the operators to a group that holds a permanent Security Administrator assignment, then enable an access review so the group membership is recertified each quarter.
  • DCreate an eligible Security Administrator assignment for each operator but leave activation settings at their defaults so operators can elevate whenever an incident occurs.
Eligible PIM assignments grant no standing access until activation, and role activation settings enforce maximum duration, approval, and multifactor authentication requirements. Privileged Identity Management distinguishes the assignment type from the activation policy. An eligible assignment means the principal holds no permissions until they activate, while the role's activation settings control how long activation lasts and whether approval and multifactor authentication are demanded. Combining eligibility with an eight-hour, approval-gated, multifactor-protected activation policy satisfies just-in-time access at least privilege.

Why A is correct: An eligible assignment grants no standing access until the operator activates it, and role activation settings enforce the eight-hour cap, approval, and multifactor authentication, matching every part of the requirement.

Why B is wrong: An active assignment grants the role permanently and is not gated by activation, so the operator carries standing privilege at all times and the eight-hour, approval-based limit never applies.

Why C is wrong: A permanently assigned group still confers standing privilege between reviews, and an access review recertifies membership rather than enforcing just-in-time activation, approval, or a time limit on use.

Why D is wrong: Eligibility removes standing access, but default activation settings do not guarantee an approval step, multifactor authentication, or the specific eight-hour duration, so the stated controls are not enforced.

See more SC-300 practice questions, answers explained.

More in this domain

Back to all Plan and Automate Identity Governance objectives, or the SC-300 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.