An identity team must ensure that members of the Security Operations group hold no standing Security Administrator permissions but can raise themselves to that role for up to eight hours when they need to respond to an incident. Activation must require approval and multifactor authentication. Which Privileged Identity Management configuration meets the requirement with the least standing privilege?
- ACreate an eligible Security Administrator assignment for each operator and set the role activation settings to a maximum eight-hour duration that requires approval and multifactor authentication. Correct
- BCreate an active Security Administrator assignment for each operator and configure the role's activation settings to require approval and multifactor authentication for every action.
- CAdd the operators to a group that holds a permanent Security Administrator assignment, then enable an access review so the group membership is recertified each quarter.
- DCreate an eligible Security Administrator assignment for each operator but leave activation settings at their defaults so operators can elevate whenever an incident occurs.
Why A is correct: An eligible assignment grants no standing access until the operator activates it, and role activation settings enforce the eight-hour cap, approval, and multifactor authentication, matching every part of the requirement.
Why B is wrong: An active assignment grants the role permanently and is not gated by activation, so the operator carries standing privilege at all times and the eight-hour, approval-based limit never applies.
Why C is wrong: A permanently assigned group still confers standing privilege between reviews, and an access review recertifies membership rather than enforcing just-in-time activation, approval, or a time limit on use.
Why D is wrong: Eligibility removes standing access, but default activation settings do not guarantee an approval step, multifactor authentication, or the specific eight-hour duration, so the stated controls are not enforced.