A security engineer needs to implement Privileged Identity Management (PIM) for a group of Azure subscription owners. The requirement states that activation must require approval and must generate an approval request to two specific managers. How should PIM be configured?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because PIM role settings for each eligible role assignment can be configured to require approval, and specific users can be designated as required approvers. When a user requests activation, a notification is sent to all configured approvers.
Full explanation below image
Full Explanation
A is correct because PIM role settings for each eligible role assignment can be configured to require approval, and specific users can be designated as required approvers. When a user requests activation, a notification is sent to all configured approvers. B is incorrect because Conditional Access policies cannot enforce manager approval workflows for role activation; they control access conditions, not approval processes. C is incorrect because PIM activation alerts combined with Logic Apps would be a custom workaround, not the built-in approval mechanism in PIM. D is incorrect because access reviews periodically validate existing memberships but do not provide real-time activation approval.