What is the difference between 'eligible' and 'active' role assignments in Azure AD Privileged Identity Management?
-
A
Eligible means the user can activate the role when needed; active means the role is always on
-
B
Eligible roles are permanent and active roles expire after 8 hours
-
C
Eligible assignments require no MFA while active assignments require MFA
-
D
Active assignments are for global admins only while eligible are for regular users