This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Answer the following questions to check your understanding of the concepts covered in this module.
A PIM role requires approval to activate, but no specific approvers were ever selected for it. A user submits an activation request. Who is being asked to approve this request?
The user who submitted the request, since they're the only one aware of it
Active Privileged Role Administrators and Global Administrators, who become the default fallback approvers
No one—the request is automatically approved since no approvers were configured
Every Global Administrator and Privileged Role Administrator in a tenant holds only eligible assignments, none active. A role requires approval to activate, and no specific approvers are configured. What happens when a user submits an activation request?
The request is automatically escalated to Microsoft support for approval
The eligible administrators can approve their own requests since they're eligible for the role
No one can approve the request, creating a tenant lockout risk
A user activates an eligible PIM role assignment that requires approval. The activation maximum duration is set to 4 hours, and the eligible assignment itself expires in 30 days. How long does the user hold the role's permissions from this one activation?
4 hours, based on the activation maximum duration
30 days, based on the eligible assignment's expiration
Indefinitely, until the user or an administrator manually deactivates the role
An administrator adds the 'New Office – All Staff' security group as a member of an administrative unit, instead of adding each user individually. Which statement about the scoped admin's resulting access is accurate?
The scoped admin can manage the group's name and membership, but can't reset passwords or manage authentication methods for the group's individual members
The scoped admin automatically gains full management rights over every member of the group
The administrative unit rejects the group, since only individual users can be added as members
Relecloud nests a smaller security group, 'New Office – Engineering,' inside a larger group, 'All Engineering,' which has a Conditional Access policy and a set of licenses assigned to it. Do the New Office group's members automatically inherit that Conditional Access policy and those licenses?
Yes—nesting one group inside another automatically extends all of the parent's assignments to the nested group's members
No—only All Engineering's direct members receive the policy and licenses; nested-group members are never included
Only the Conditional Access policy is inherited by nested members; licenses are never inherited under any circumstances
A project coordinator at Relecloud needs to invite external guests to a single project, without gaining the ability to manage every other user account in the directory. Which role provides the least-privileged way to delegate this task?
Guest Inviter
User Administrator
Global Administrator
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?