Plan and automate identity governance2 / 5
You are configuring PIM for Groups in the Microsoft Entra admin center. Your organization wants just-in-time access to Microsoft Entra roles via groups. For each of the following statements, select Yes if the statement is true. Otherwise, select No. 1. PIM for Groups allows just-in-time activation of both group membership and group ownership. 2. Role-assignable groups can have other groups nested inside them as active members. 3. PIM for Groups can provide just-in-time access to Azure roles, Key Vault, Intune, and third-party applications. 4. For roles with SharePoint/Exchange permissions, Microsoft recommends active user-to-group assignments with eligible group-to-role assignments.
CorrectIncorrect
Alex
PIM for Groups enables just-in-time activation of both group membership and group ownership (docs.microsoft.com/entra/id-governance/privileged-identity-management). Statement 1: Yes — PIM for Groups supports JIT membership and ownership activation. Statement 2: No — role-assignable groups cannot have other groups nested inside them as active members per Microsoft Learn docs. Statement 3: Yes — PIM for Groups provides JIT access to Microsoft Entra roles, Azure roles, Azure SQL, Azure Key Vault, Intune, and third-party applications. Statement 4: Yes — for roles with SharePoint/Exchange permissions, Microsoft recommends active user-to-group assignments with eligible group-to-role assignments to avoid activation delays, since SharePoint/Exchange do not support real-time propagation of JIT membership. Exam tip: PIM for Groups = JIT membership + ownership. Role-assignable groups cannot nest groups. Use active user-to-group for SharePoint/Exchange roles.
Sourcelearn.microsoft.com
Follow-up answers are available in the app. Create a free account — no credit card required.
Question 2 of 5
Create a free account