@Delos Santos, Joseph Thank you for reaching out to us, Yes it is possible to achieve your ask via PIM. I have tested the same in my tenant and was able to create the same requirement like you mentioned above.
Refer to this article: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-change-default-settings on how to configure this requirement.
Let me know if you have any further questions, feel free to post back or if you need any help we can connect offline and configure further on the same.
Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.