Your security team wants to grant engineers temporary Owner rights on a production subscription only when needed. Requirements: assignments must be time-bound (maximum 8 hours), require approval by a duty manager and MFA at activation, and be re-certified quarterly. What should you configure? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Use Azure AD PIM for Azure resources to make engineers eligible for Owner with an activation policy that requires approval and MFA, and limits duration to 8 hours, Create a recurring PIM access review for the subscription Owner role to require attestation every quarter and remove users who do not respond.
Why this is the answer
The correct options address all requirements. Azure AD PIM (Privileged Identity Management) for Azure resources allows engineers to be eligible for the Owner role, not permanently assigned. Its activation policy can enforce approval by a duty manager, MFA at activation, and a time limit of 8 hours, fulfilling the temporary, approved, and time-bound criteria. A recurring PIM access review for the Owner role ensures quarterly re-certification, removing users who don't attest their need for access. Assigning Owner directly is incorrect because it grants permanent access, violating the temporary and time-bound requirements. Azure AD access reviews for Microsoft 365 group membership are irrelevant here as the question concerns direct role assignments on an Azure subscription, not group membership. Creating an Azure Policy to remove the Owner role after 8 hours is not a native PIM feature and would be a complex, less robust solution compared to PIM's built-in activation policies.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed