A canal-lock Owner role is eligible in PIM, and the security engineer wants a second factor plus a typed business reason before activation. Where should those requirements be configured?
Select an answer to reveal the explanation.
Short Explanation
Put the bouncer at the PIM activation door for that Azure role: check MFA and make them write why they need the lock Owner hat. That is a PIM role setting—not a blanket ID Protection policy for the whole tenant.
Full Explanation
PIM activation settings on an Azure resource role can require multifactor authentication, justification, and optionally approval before an eligible assignment becomes active. Those controls are configured per role on the resource in PIM. Microsoft Entra ID Protection addresses identity risk signals and is not the primary place to define Azure resource role activation gates.