A security team is implementing Entra ID PIM access reviews for the 'Cognitive Services Contributor' role. The review is quarterly, and active role assignments that are not reviewed within 30 days should be automatically removed. The security team also wants to require a justification from the reviewers. Which PIM access review settings achieve this?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because Microsoft Entra PIM access reviews for roles support all the required configurations: (1) quarterly recurrence for the review schedule, (2) 30-day review duration after which non-responses are acted upon, (3) 'Remove access' as the action when reviewers don't respond—ensuring unreviewed assignments are removed automatically, and (4) the 'Require justification from reviewer' setting forces reviewers to provide a business reason when approving continued access. B is wrong because monthly recurrence is more frequent than quarterly (mismatches the requirement) and 7 days is too short for the specified 30-day window.
Full explanation below image
Full Explanation
A is correct because Microsoft Entra PIM access reviews for roles support all the required configurations: (1) quarterly recurrence for the review schedule, (2) 30-day review duration after which non-responses are acted upon, (3) 'Remove access' as the action when reviewers don't respond—ensuring unreviewed assignments are removed automatically, and (4) the 'Require justification from reviewer' setting forces reviewers to provide a business reason when approving continued access. B is wrong because monthly recurrence is more frequent than quarterly (mismatches the requirement) and 7 days is too short for the specified 30-day window. C is wrong because role expiration without access reviews removes the certification process where reviewers confirm continued need; it is time-bound auto-removal, not a periodic review with human judgment. D is wrong because 'Approve access' for non-respondents is the opposite of the requirement—it keeps access for users whose need was not confirmed by a reviewer.