This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage identity, access, and governance (20–25%)
--> Secure access to resources by using Microsoft Entra ID
--> Implement and configure Privileged Identity Management (PIM)
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Microsoft Entra Privileged Identity Management (PIM) is a Microsoft Entra ID Governance capability that helps organizations manage, control, and monitor privileged access to resources.
The primary security objective of PIM is to reduce the risks associated with standing privileged access. Rather than giving administrators permanent access to highly privileged roles, PIM can make users eligible for those roles and require them to activate the role only when they need it.
This approach is commonly called just-in-time (JIT) privileged access.
PIM is particularly important for protecting highly privileged roles such as:
- Global Administrator
- Privileged Role Administrator
- Security Administrator
- User Administrator
- Application Administrator
- Other Microsoft Entra built-in or custom roles
- Azure resource roles such as Owner, Contributor, and User Access Administrator
PIM can also be used with Azure resource roles and groups, providing a broader privileged-access-management strategy.
1. Why Privileged Identity Management Is Important
Traditional role assignment often creates a problem:
A user receives powerful permissions and retains those permissions whether or not they are currently performing privileged work.
For example, suppose an administrator is assigned the Global Administrator role permanently.
When the administrator needs to configure Microsoft Entra ID, that access is necessary.
However, when the administrator is simply reading email or working on an unrelated task, the Global Administrator privileges are still available.
This creates a larger attack surface.
If the administrator’s account is compromised, an attacker may immediately inherit the administrator’s privileges.
PIM addresses this problem by allowing the administrator to be eligible rather than permanently active.
The administrator activates the role when needed, and the elevated access can automatically expire after a defined period.
Traditional standing access
User → Permanent privileged role → Privileges always available
PIM-based JIT access
User → Eligible for privileged role → Activation → Temporary privileged access → Automatic expiration
The second model supports the principle of least privilege and significantly reduces the amount of time highly privileged permissions are available.
2. PIM Assignment Types
One of the most important concepts for the SC-500 exam is understanding the difference between Eligible and Active assignments.
Eligible assignment
An eligible assignment means that the user is authorized to activate the role, but doesn’t currently have the role’s privileges.
The user must perform the required activation process before receiving the privileges.
Depending on the configuration, activation might require:
- Multifactor authentication
- A business justification
- Ticket information
- Approval
- Additional authentication requirements
- A specified activation duration
Example
John is an eligible Global Administrator.
John isn’t currently a Global Administrator.
When John needs to perform a privileged operation, he activates the role.
PIM then temporarily activates the assignment.
Active assignment
An active assignment means the user already has the role’s permissions.
The user doesn’t have to activate the role before using it.
For example:
Sarah has an active Security Administrator assignment.
Sarah can immediately use the Security Administrator privileges.
This is essentially standing access, although PIM can still apply duration controls to active assignments.
Eligible vs. Active
| Characteristic | Eligible | Active |
|---|---|---|
| Has privileges immediately? | No | Yes |
| Requires activation? | Yes | No |
| Supports JIT access? | Yes | No |
| MFA can be required at activation? | Yes | Not as an activation requirement |
| Approval can be required? | Yes | No activation approval |
| Justification can be required? | Yes | No activation justification |
| Can be time-bound? | Yes | Yes |
| Best for least privilege? | Yes | Generally no |
Exam tip
If a question says:
“Administrators should have access only when they need it.”
Think:
Eligible assignment + activation = JIT access
3. Permanent vs. Time-Bound Assignments
PIM also distinguishes between permanent and time-bound assignments.
Permanent eligible
The user remains eligible indefinitely.
They still must activate the role before using it.
Example:
A full-time security administrator is permanently eligible for Security Administrator.
The administrator can activate the role whenever necessary, subject to the configured PIM policies.
Time-bound eligible
The user’s eligibility exists only during a specified period.
Example:
A contractor is eligible for Contributor access from September 1 through September 30.
After September 30, the eligibility expires.
This is especially useful for:
- Contractors
- Temporary projects
- Mergers and acquisitions
- Incident-response teams
- Temporary administrative responsibilities
Permanent active
The user permanently has the privileges without activation.
This provides the least amount of privilege protection among these options.
Time-bound active
The user has the privileges during a specified period, but doesn’t need to activate them.
For example:
A consultant has active Contributor access from September 1 through September 15.
During that period, the consultant can immediately use the role.
4. Just-In-Time Access
Just-in-time access is one of the fundamental security concepts behind PIM.
Instead of providing privileged permissions continuously, access is granted temporarily when required.
The general process is:
- User is assigned an eligible role.
- User needs to perform privileged work.
- User requests activation.
- PIM evaluates the activation requirements.
- User completes required security controls.
- Role becomes active.
- User performs the privileged task.
- Activation expires.
This reduces the amount of time privileged permissions are exposed.
Example
An administrator normally doesn’t need Global Administrator permissions.
The administrator receives an alert that a tenant-wide configuration change is required.
The administrator:
- Opens PIM.
- Selects Global Administrator.
- Requests activation.
- Completes MFA.
- Provides a justification.
- Receives approval if required.
- Gets temporary Global Administrator access.
- Performs the required task.
- Access automatically expires.
5. Configuring PIM Role Settings
PIM role settings, also called PIM policies, determine what users must do when activating a role and how long assignments can remain active.
Role settings are configured for individual roles.
Important settings include:
- Activation maximum duration
- MFA requirements
- Conditional Access authentication context
- Authentication strength
- Justification requirements
- Ticket information requirements
- Approval requirements
- Eligible assignment duration
- Active assignment duration
- Notifications
6. Activation Maximum Duration
The activation maximum duration specifies the maximum amount of time a user can have an activated eligible role.
For example:
Maximum activation duration = 2 hours
A user can activate the role for a period up to two hours.
After the activation expires, the user must activate the role again if additional privileged work is necessary.
Microsoft Entra PIM currently allows the activation maximum duration for Microsoft Entra roles to be configured from 1 to 24 hours.
Security consideration
A shorter activation duration generally reduces the window during which privileged access can be abused.
However, setting the duration too short can create unnecessary administrative friction.
The goal is to choose a duration appropriate to the organization’s operational requirements.
7. Require Multifactor Authentication on Activation
PIM can require multifactor authentication (MFA) when a user activates an eligible role.
This creates an additional security barrier between the user’s normal account and privileged access.
For example:
A user signs into Microsoft Entra ID normally and later attempts to activate Global Administrator.
PIM can require the user to perform MFA before the role becomes active.
Important distinction
MFA requirements for activation should not be confused with MFA requirements for creating an active assignment.
PIM can also require MFA when an administrator creates an active assignment, but that doesn’t mean PIM will repeatedly enforce MFA whenever the user uses the already-active role.
8. Conditional Access Authentication Context
PIM can use Microsoft Entra Conditional Access authentication context to impose stronger authentication requirements when a privileged role is activated.
This can be useful when simply requiring a generic MFA check isn’t sufficient.
For example, an organization could require a stronger authentication method for privileged operations than it requires for ordinary sign-in.
Authentication strength policies can be used together with authentication context to establish stronger requirements.
Exam scenario
If a question asks for:
“Require stronger authentication specifically when a privileged role is activated.”
Consider:
Conditional Access authentication context + appropriate authentication strength
9. Require Justification
PIM can require the user to provide a business justification when activating a role.
For example:
“Activating Security Administrator to investigate suspicious sign-in activity.”
The justification provides context for why privileged access was required.
This supports:
- Accountability
- Auditing
- Security investigations
- Compliance
- Operational review
Important distinction
A justification explains why access is needed.
It doesn’t itself provide authorization.
10. Require Ticket Information
PIM can also require users to provide ticket information during activation.
For example:
INC00123456
This allows an organization to associate privileged activity with a service-management or incident-management ticket.
However, an important detail is that PIM’s ticket-information field is informational.
PIM doesn’t inherently validate the ticket against an external ticketing system.
Exam tip
If a question says:
“Require administrators to provide a change or incident ticket number when activating a privileged role.”
Think:
Require ticket information on activation.
11. Require Approval
PIM can require an eligible user to obtain approval before the role becomes active.
The workflow is approximately:
User requests activation → Approval required → Approver reviews request → Approve/Deny → Role activates if approved
An organization can configure one or more designated approvers.
For important privileged roles, having multiple possible approvers can improve availability and reduce the risk of a single point of failure.
Example
An organization wants every Global Administrator activation to be approved.
The user submits:
- Requested role
- Requested duration
- Business justification
- Ticket information
The designated approver reviews the request.
If approved, the role becomes active for the permitted duration.
12. Approval Is Different from Eligibility
This distinction is important.
Being eligible doesn’t necessarily mean that approval is required.
An eligible user may be able to activate immediately if the PIM policy only requires MFA and justification.
Alternatively, the policy can require approval.
Therefore:
Eligible describes the user’s assignment status.
Approval required describes an activation policy.
These are different concepts.
13. Notifications
PIM provides notifications associated with privileged-role management and activation.
Notifications can help security teams and administrators identify:
- Role assignments
- Activation activity
- Approval requests
- Changes to privileged access
- Other PIM-related events
Notifications can be used as part of a broader privileged-access monitoring strategy.
14. Assigning a Role Through PIM
A typical administrator workflow for assigning a Microsoft Entra role through PIM is:
- Open the Microsoft Entra admin center.
- Open ID Governance.
- Open Privileged Identity Management.
- Select Microsoft Entra roles.
- Select the appropriate role.
- Select Add assignments.
- Select the member.
- Select Eligible or Active.
- Configure the assignment duration.
- Complete the assignment.
The appropriate administrator permissions are required to manage these assignments.
For Microsoft Entra role PIM settings, the Privileged Role Administrator role is an important administrative role to know for the exam.
15. Activating an Eligible Role
When an eligible user needs privileged access, the user initiates an activation request.
A typical activation workflow is:
- Open Microsoft Entra PIM.
- Locate the eligible role.
- Select Activate.
- Specify the requested duration.
- Complete additional verification if required.
- Provide justification if required.
- Provide ticket information if required.
- Submit the activation.
- Wait for approval if required.
- Use the role while it is active.
Once the activation expires, the privileges are removed.
16. Limiting the Activation Scope
PIM can support limiting the scope of access when activating certain roles.
This is particularly important because the principle of least privilege says that administrators shouldn’t request broader access than necessary.
For example, if an administrator only needs access to a particular resource, the administrator should avoid requesting access to an unnecessarily broad scope when the relevant PIM configuration supports a narrower scope.
Security principle
Give the administrator the smallest scope and shortest duration necessary to complete the task.
17. Deactivating a Role Early
PIM doesn’t require users to wait until the activation period expires.
If a user finishes their privileged work early, the user can deactivate the role.
For example:
Maximum activation duration = 4 hours
Administrator finishes the task after 45 minutes.
The administrator can deactivate the role rather than leaving it active for the remaining 3 hours and 15 minutes.
This is another application of least privilege.
18. PIM for Azure Resources
PIM isn’t limited to Microsoft Entra directory roles.
PIM can also manage Azure resource roles.
Examples include:
- Owner
- Contributor
- User Access Administrator
- Other Azure RBAC roles
For Azure resources, PIM can provide:
- Eligible assignments
- Active assignments
- Time-bound assignments
- Activation
- MFA requirements
- Approval workflows
- Justification
- Auditability
- Scope controls
Example
Instead of permanently assigning:
User → Subscription Owner
an organization could use:
User → Eligible Owner → Activate when necessary → Temporary Owner → Expire
This significantly reduces standing privileged access to Azure resources.
19. PIM for Groups
PIM can also be used with groups.
This allows organizations to manage privileged membership in groups through PIM.
For example, imagine a group called:
Production-Administrators
Membership in this group grants administrative privileges.
Instead of permanently making an administrator a member of the group, PIM can allow the user to become eligible for group membership and activate that membership when needed.
This provides another way to implement JIT access.
20. PIM and Least Privilege
PIM should be viewed as one component of a broader least-privilege strategy.
A good privileged-access design should consider:
Who?
Only authorized administrators should receive privileged access.
What?
Assign the smallest role necessary.
Where?
Limit access to the required scope.
When?
Provide access only when necessary.
How long?
Use the shortest practical activation duration.
Under what conditions?
Require appropriate authentication, justification, approval, and other controls.
This results in the security principle:
Right person + right privilege + right scope + right time + right conditions
21. PIM and Emergency Access Accounts
Organizations should maintain emergency access accounts, sometimes called break-glass accounts, for situations where normal administrative access isn’t available.
This is particularly important when configuring PIM.
For example, imagine that:
- All Privileged Role Administrators are eligible rather than active.
- Activation requires approval.
- No approvers are configured.
Administrators could potentially lock themselves out of the tenant.
Emergency access accounts provide a recovery mechanism for scenarios such as:
- Incorrect PIM configuration
- Conditional Access misconfiguration
- Authentication problems
- Loss of administrator access
- Other tenant-wide administrative emergencies
Emergency access accounts should themselves be carefully protected and monitored.
22. PIM and Access Reviews
PIM can be used alongside access reviews to periodically evaluate whether users still need privileged access.
For example:
50 users are eligible for a privileged role.
A periodic access review can determine:
- Who still needs eligibility?
- Who has changed responsibilities?
- Who should be removed?
- Who should have a less privileged role?
This helps prevent privilege accumulation over time.
23. PIM and Auditability
Privileged access should be observable.
PIM provides information that can help organizations understand:
- Who was assigned a role
- Who activated a role
- When activation occurred
- How long access was requested
- Whether approval was required
- Who approved or denied requests
- Why the user requested access
This information can support:
- Security investigations
- Compliance
- Auditing
- Incident response
- Administrative accountability
24. Discovery and Insights
PIM provides capabilities that help organizations identify privileged assignments and improve their privileged-access posture.
For example, organizations can identify users with standing privileged assignments and consider converting them to eligible assignments.
The objective is to reduce unnecessary permanent privileged access.
A common improvement process is:
Discover privileged access → Evaluate necessity → Remove unnecessary access → Convert standing access to eligible access → Configure activation controls → Monitor
25. Common PIM Security Recommendations
For an SC-500 exam scenario, strong PIM implementations generally follow these principles:
1. Prefer eligible assignments
Use eligible assignments instead of permanent active assignments whenever operationally practical.
2. Use JIT activation
Allow privileged access only when it is needed.
3. Require MFA
Require strong authentication when activating sensitive roles.
4. Require justification
Make administrators explain why privileged access is needed.
5. Require approval for highly sensitive roles
Use approval workflows where an additional authorization step is appropriate.
6. Limit activation duration
Don’t provide eight hours of privileged access for a task that takes 20 minutes.
7. Limit assignment scope
Don’t give subscription-wide access when resource-level access is sufficient.
8. Review privileged access regularly
Remove users who no longer require privileged permissions.
9. Maintain emergency access
Ensure that a PIM or Conditional Access configuration problem doesn’t permanently lock administrators out.
10. Monitor privileged activity
Use logs, alerts, Microsoft Defender capabilities, and Microsoft Sentinel as appropriate to detect suspicious privileged activity.
26. Common Exam Traps
Trap 1: Eligible doesn’t mean active
An eligible user does not currently have the role’s privileges.
They must activate the role.
Trap 2: Active doesn’t mean activation is required
An active assignment is already usable.
The user doesn’t have to activate it.
Trap 3: Justification isn’t approval
A justification explains why the user wants access.
Approval requires another designated person to approve the activation request.
Trap 4: Time-bound isn’t the same as JIT
A time-bound assignment has a start/end period.
JIT generally refers to activating privileges when they are needed for a limited period.
An eligible assignment can be both time-bound and JIT.
Trap 5: MFA isn’t the same as Conditional Access authentication context
MFA can be required during activation.
Authentication context can be used when the organization needs a specific Conditional Access-based authentication requirement for the privileged operation.
Trap 6: Ticket information isn’t ticket validation
PIM can require ticket information, but the ticket field is informational and isn’t inherently validated against an external ticketing system.
Trap 7: PIM isn’t just for Global Administrator
PIM can manage many Microsoft Entra roles and Azure resource roles.
27. SC-500 Quick Reference
| Concept | Remember |
|---|---|
| PIM | Controls and governs privileged access |
| JIT | Give privileged access only when needed |
| Eligible | User can activate the role |
| Active | User already has the role |
| Permanent eligible | Eligible indefinitely |
| Time-bound eligible | Eligible only during a defined period |
| Permanent active | Privileges continuously available |
| Time-bound active | Privileges available during a defined period |
| Activation | Converts eligible access into active access temporarily |
| MFA | Can be required during activation |
| Authentication context | Can enforce additional Conditional Access authentication requirements |
| Justification | Explains why privileged access is needed |
| Ticket information | Records a ticket/reference number |
| Approval | Requires designated approver authorization |
| Activation duration | Limits how long activated access remains active |
| Least privilege | Give only required permissions |
| JIT + eligible | Preferred pattern for reducing standing privilege |
| Access reviews | Periodically validate whether access is still needed |
| Emergency access | Recovery mechanism for administrative lockout |
| Azure resource PIM | Applies PIM concepts to Azure RBAC roles |
| PIM for Groups | Controls privileged group membership |
Practice Exam Questions
Question 1
An organization wants its administrators to have Global Administrator permissions only when they are actively performing a privileged task. Administrators should normally have no Global Administrator privileges, but they must be able to obtain them when necessary.
Which PIM assignment type should you use?
A. Active
B. Eligible
C. Permanent active
D. Time-bound active
Answer: B
Explanation: An eligible assignment allows a user to activate a privileged role when needed. Before activation, the user doesn’t have the role’s privileges. This is the fundamental PIM pattern for just-in-time access.
Question 2
A company requires administrators activating the Security Administrator role to provide a business reason for the activation. The company doesn’t want another administrator to approve the request.
Which PIM setting should you configure?
A. Require approval to activate
B. Require ticket information on activation
C. Require justification on activation
D. Require MFA on active assignment
Answer: C
Explanation: Require justification on activation requires the administrator to provide a business reason for activating the eligible role. Approval isn’t required unless the approval setting is separately enabled.
Question 3
An organization wants Global Administrator activations to require authorization from another designated administrator before the role becomes active.
Which PIM capability should be configured?
A. Activation maximum duration
B. Require approval to activate
C. Require ticket information
D. Access reviews
Answer: B
Explanation: Require approval to activate creates an approval workflow for eligible-role activation. Designated approvers review and approve or deny activation requests.
Question 4
A user has an eligible Contributor assignment for an Azure subscription. The user activates the assignment and selects a four-hour activation period. After completing the required work in one hour, what should the user do to minimize the amount of time privileged access remains available?
A. Deactivate the role
B. Convert the assignment to active
C. Extend the activation period
D. Create another eligible assignment
Answer: A
Explanation: The user should deactivate the role after completing the privileged task. This follows the principle of least privilege by reducing the time that elevated permissions remain active.
Question 5
A security team wants to ensure that users cannot activate a privileged role for more than two hours at a time.
Which PIM configuration should the security team modify?
A. Assignment expiration
B. Approval workflow
C. Activation maximum duration
D. Access review frequency
Answer: C
Explanation: Activation maximum duration controls the maximum amount of time an eligible role can remain activated. For Microsoft Entra roles, this setting can be configured from 1 to 24 hours.
Question 6
An organization wants administrators to provide an incident or change ticket number whenever they activate a privileged role. The organization does not require PIM to validate the ticket against its external ticketing system.
Which PIM setting should be used?
A. Require justification on activation
B. Require approval to activate
C. Require authentication context
D. Require ticket information on activation
Answer: D
Explanation: Require ticket information on activation prompts the user to provide ticket information. The information is recorded for context, but PIM doesn’t inherently validate the ticket against an external ticketing system.
Question 7
A security architect wants privileged administrators to use stronger authentication when activating a sensitive role. The organization specifically wants to use Microsoft Entra Conditional Access authentication context together with an authentication strength policy.
Which capability addresses this requirement?
A. Authentication context
B. Access reviews
C. Assignment duration
D. Ticket information
Answer: A
Explanation: Conditional Access authentication context can be used with authentication strengths to require specific authentication requirements during privileged-role activation.
Question 8
An administrator has a permanent active assignment for a highly privileged Microsoft Entra role. The security team wants the administrator to retain the ability to obtain the role but not continuously possess its permissions.
What should the security team do?
A. Make the assignment permanently active
B. Convert the assignment to eligible
C. Increase the activation maximum duration
D. Remove MFA requirements
Answer: B
Explanation: Converting the assignment to eligible allows the administrator to activate the role when needed rather than continuously having its privileges. This is a core PIM strategy for reducing standing privileged access.
Question 9
An organization requires all privileged-role activations to be approved. All Privileged Role Administrators are eligible for the Privileged Role Administrator role, but no specific approvers have been configured.
Why is this configuration potentially dangerous?
A. Users will automatically receive permanent active assignments
B. PIM will disable all Conditional Access policies
C. Administrators may be unable to activate the role and could potentially lock themselves out of the tenant
D. Eligible assignments will automatically become permanent
Answer: C
Explanation: If all privileged administrators are only eligible, activation requires approval, and no appropriate approvers are available, administrators may be unable to activate their privileged roles. Organizations should carefully configure approvers and maintain appropriate emergency access mechanisms.
Question 10
A company has several contractors who require Contributor permissions during a three-month project. The contractors should be able to activate the role only during those three months, and the privileges shouldn’t remain continuously active.
Which configuration best meets the requirement?
A. Permanent active assignment
B. Permanent eligible assignment
C. Time-bound active assignment
D. Time-bound eligible assignment
Answer: D
Explanation: A time-bound eligible assignment limits the period during which the contractor can activate the role while still requiring activation before the privileges are granted. This combines time-limited eligibility with just-in-time access.
Final Exam Takeaways
For SC-500, the most important PIM concepts to be able to distinguish quickly are:
- Eligible vs. Active
- Permanent vs. Time-bound
- Just-in-time activation
- Activation maximum duration
- MFA during activation
- Conditional Access authentication context
- Authentication strength
- Justification
- Ticket information
- Approval workflows
- Least-privilege scope
- Early deactivation
- PIM for Microsoft Entra roles
- PIM for Azure resource roles
- PIM for Groups
- Access reviews
- Emergency access accounts
- Monitoring and auditing privileged activity
The single most useful mental model for scenario questions is:
Eligible → Activate → Verify/Justify/Approve → Temporarily Active → Deactivate/Expire
If a scenario describes standing administrative access that should be available only when needed, the answer will very often involve PIM + an eligible assignment + JIT activation, with MFA, approval, justification, limited duration, or other controls layered on according to the requirements.
Go to the SC-500 Exam Prep Hub main page
