This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Answer the following questions to check your understanding of the key concepts covered in this module.
A security engineer is reviewing PIM assignments for a team of 15 analysts who all need the same eligible access to a production resource group. Each analyst currently has an individual eligible assignment with slightly different activation durations. What is the most significant risk of this configuration?
The analysts experience more activation friction than necessary.
Nonuniform activation settings across individual assignments create policy drift that auditors flag and attackers probe for.
Individual eligible assignments exceed the maximum number of assignments allowed per resource group.
An AI pipeline agent needs read access to an Azure Blob Storage container to retrieve inference inputs. A security engineer proposes making the agent's identity eligible for the Storage Blob Data Reader role in PIM. Why is this approach incorrect?
The Storage Blob Data Reader role doesn't support PIM eligible assignments.
Managed identities and service principals can't perform interactive PIM activation, so eligible assignments aren't supported for workload identities.
PIM for Azure resource roles only supports user identities at the subscription scope, not resource scope.
A team is configuring PIM for a Global Administrator role. They want to ensure that no single engineer can elevate to Global Administrator without a second person approving the request. Which PIM activation control should they configure?
Set the maximum activation duration to 1 hour.
Require justification on activation.
Require approval to activate the role, and designate at least two approvers.
A production subscription is protected by PIM with eligible assignments. The organization's two primary PIM approvers are both unavailable during a critical outage. Which account type is designed to handle this scenario?
A service account with an active Global Administrator assignment.
A break-glass emergency access account with a permanent Global Administrator assignment, excluded from PIM activation requirements.
An extra eligible assignment for a backup administrator with a lower approval threshold.
A security engineer is configuring PIM for Groups to manage access to a set of production Azure resources. They create a standard Microsoft Entra security group, assign it the necessary roles, and make team members eligible for group membership. What security risk does using a role-assignable group instead mitigate?
A standard group doesn't support eligible membership assignments in PIM for Groups.
Lower-privileged administrators such as Groups Administrators can modify standard group membership outside the PIM workflow, potentially bypassing the activation audit trail.
Standard groups don't support MFA enforcement during PIM activation.
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?