A security engineer is implementing Microsoft Entra Privileged Identity Management (PIM) for roles that grant access to sensitive AI resources. The engineer wants to require users to provide a justification and receive manager approval before being assigned the 'Cognitive Services OpenAI Contributor' role. Which PIM setting configures this?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because in Microsoft Entra PIM, setting a role as 'Eligible' means users must explicitly activate the role before using it. In the role's activation settings, you can require a business justification, require approval from designated approvers, and set a maximum activation duration.
Full explanation below image
Full Explanation
B is correct because in Microsoft Entra PIM, setting a role as 'Eligible' means users must explicitly activate the role before using it. In the role's activation settings, you can require a business justification, require approval from designated approvers, and set a maximum activation duration. This enforces just-in-time access with human approval. A is wrong because an 'Active' assignment grants the role continuously without requiring activation or approval. C is wrong because PIM for Groups is a valid feature but does not by itself add the approval workflow; you still need to configure activation settings. D is wrong because access reviews periodically review existing assignments but do not add an approval step to role activation.