You want to minimize standing privileges for Global Administrator. Admins should request just-in-time elevation, be prompted for MFA and approval by the security team, and automatically lose the elevation after two hours. You also want a monthly validation that only necessary users retain eligibility. What should you configure? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: In PIM, assign Global Administrator as Eligible to the admins and configure activation to require approval and MFA with a two-hour maximum duration., In PIM, create a recurring monthly access review scoped to the Global Administrator role to remove unneeded or inactive eligible assignments..
Why this is the answer
The correct options leverage Azure AD Privileged Identity Management (PIM) to implement just-in-time (JIT) access and regular access reviews. Assigning Global Administrator as "Eligible" in PIM, with activation requiring approval and MFA for a two-hour maximum duration, directly addresses the need for minimized standing privileges, JIT elevation, MFA, security team approval, and automatic de-elevation. Creating a recurring monthly access review in PIM for the Global Administrator role ensures monthly validation that only necessary users retain eligibility, removing unneeded or inactive assignments. Making admins Permanent Active in the Global Administrator role, even with MFA, violates the principle of least privilege and standing privileges. Azure AD Identity Protection focuses on risk detection and remediation, not managing access reviews for specific roles. Adding admins to a break-glass group is for emergency access when other systems fail, not for routine, controlled elevation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed