exam questions

Exam MS-102 All Questions

View all questions & answers for the MS-102 exam

Exam MS-102 topic 1 question 280 discussion

Actual exam question from Microsoft's MS-102
Question #: 280
Topic #: 1
[All MS-102 Questions]

HOTSPOT
-

You have a Microsoft 365 E5 subscription.

You need to configure Privileged Identity Management (PIM) for the User Administrator role in Microsoft Entra. Eligible users must meet the following requirements:

• Always be able to request the User Administrator role
• Must provide a reason when requesting the User Administrator role
• Must require multi-factor authentication (MFA) when activating the User Administrator role

The solution must minimize administrative effort.

How should you configure the Role settings for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
oopspruu
Highly Voted 1 year ago
The answer for last one is option 3.
upvoted 8 times
Murad01
10 months ago
Agree with option 3 for last one
upvoted 3 times
004b54b
1 month ago
Box3 = 3: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-change-default-settings "If your goal is to ensure that users must provide authentication during activation, you can use On activation, require Microsoft Entra Conditional Access authentication context together with Authentication Strengths."
upvoted 1 times
...
...
...
APK1
Highly Voted 8 months, 3 weeks ago
Box1=3 Set Allow Permanent Eligible Assignments to YES Box2=1 Select Require Justification on Activation Box3=3 Set Require Azure Multi-Factor Authentication on the Active Assignments to YES
upvoted 5 times
...
Frank9020
Most Recent 6 months ago
Given answers are correct
upvoted 1 times
...
Ody
6 months ago
Given answer is correct: Set Allow permanent eligible assignment to yes Set Require justification on activation On activation, require multifactor authentication The third option means you can require users who are eligible for a role to prove who they are by using the multifactor authentication feature in Microsoft Entra ID before they can activate. This option is not correct: Require multifactor authentication on active assignment - You can require that administrators provide multifactor authentication when they create an active (as opposed to eligible) assignment. https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-change-default-settings
upvoted 4 times
...
Xive
6 months, 2 weeks ago
given answer is correct.
upvoted 2 times
...
Tr619899
7 months, 1 week ago
1. Always be able to request the User Administrator role: Set Allow permanent eligible assignment to yes. This allows users to always request the role without needing approval. 2. Must provide a reason when requesting the User Administrator role: Select Require justification on activation. This ensures users provide a reason when activating the role. 3. Must require MFA when activating the User Administrator role: Set On activation, require Azure MFA to ensure MFA is used during role activation.
upvoted 2 times
...
yaboo1617
8 months, 3 weeks ago
Correct https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-change-default-settings
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago