SC-300 Privileged Identity Management (PIM) 1 — Questions and Answers
Question 1: In Azure AD Privileged Identity Management, what is the difference between an 'eligible' assignment and an 'active' assignment?
- Eligible assignments are permanent; active assignments are time-limited
- Eligible users must activate their role before using it; active users have the role immediately without activation (Correct answer)
- Eligible assignments require approval; active assignments do not
- Eligible assignments apply to groups; active assignments apply to users
Correct answer: Eligible users must activate their role before using it; active users have the role immediately without activation
Eligible assignments require users to go through an activation process (with optional MFA and approval) before the role becomes active, whereas active assignments grant the role immediately.
Question 2: What is the default maximum activation duration for a PIM role assignment?
- 1 hour
- 4 hours
- 8 hours (Correct answer)
- 24 hours
Correct answer: 8 hours
PIM's default maximum activation duration is 8 hours, though administrators can configure this value between 1 and 24 hours per role.
Question 3: Which PIM feature requires a second administrator to approve a role activation request before the role becomes active?
- Activation maximum duration
- Require justification on activation
- Require approval to activate (Correct answer)
- Require Azure MFA on activation
Correct answer: Require approval to activate
The 'Require approval to activate' setting in PIM role settings mandates that a designated approver reviews and approves the activation request before the role is granted.
Question 4: You want to ensure that all eligible Global Administrator role activations are recorded with a business justification. Which PIM role setting should you enable?
- Require ticket information on activation
- Require justification on activation (Correct answer)
- Require approval to activate
- Require Azure MFA on activation
Correct answer: Require justification on activation
Enabling 'Require justification on activation' forces users to enter a reason before their role activation is processed.
Question 5: In PIM, which role is required to manage role assignments for Azure AD directory roles?
- Security Administrator
- Global Administrator or Privileged Role Administrator (Correct answer)
- Identity Governance Administrator
- User Administrator
Correct answer: Global Administrator or Privileged Role Administrator
The Global Administrator and Privileged Role Administrator roles have the authority to configure PIM settings and manage directory role assignments in PIM.
Question 6: Which PIM capability sends email notifications to designated reviewers when an access review for a privileged role is ready for review?
- PIM alerts
- Access reviews
- Role settings audit log
- Notifications in role settings (Correct answer)
Correct answer: Notifications in role settings
PIM role settings include a 'Notifications' section where administrators can configure email alerts sent to reviewers, approvers, and role members for key events.
In Azure AD Privileged Identity Management, what is the difference between an 'eligible' assignment and an 'active' assignment?