問題文
Administrators at a company hold the Azure Backup Contributor role permanently. Security wants them to keep the same permissions but only while they are actually performing a restore, and each use must be justified and recorded. Which Microsoft Entra Privileged Identity Management assignment type meets this requirement?
選択肢
- Assign the role as active with a start and end date.
- Assign the role as eligible, so administrators activate it when needed.
- Remove the role and grant it again each time a restore is requested.
- Assign the role as permanent active, and enable sign-in risk policies to record each activation.