Three platform engineers still have permanent active Owner on production. Which PIM assignment setting should the security engineer change for that Azure resource role?
Select an answer to reveal the explanation.
Short Explanation
Permanent active Owner is a key glued into the lock. Flip off “allow permanent active assignment” for that Azure role so every Owner stint gets an expiration date—or sits eligible until someone activates it on purpose.
Full Explanation
PIM assignment settings can disallow permanent active (and separately control permanent eligible) assignments for an Azure resource role, forcing end dates on standing privileged access. Extending or renewing assignments is a supporting workflow; security defaults do not manage Azure RBAC Owner permanence.