Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraHard
A security auditor observes that several users have been assigned highly privileged roles in Microsoft Entra ID for an extended period, even though they only require these permissions for specific, infrequent tasks. The auditor recommends implementing a solution that provides just-in-time (JIT) access and requires multi-factor authentication (MFA) and a business justification for activating these roles. Which Microsoft Entra capability should be configured to meet these recommendations?
- AMicrosoft Entra Conditional Access
- BMicrosoft Entra Privileged Identity Management (PIM)
- CMicrosoft Entra Access Reviews
- DMicrosoft Entra Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Entra Privileged Identity Management (PIM)
Microsoft Entra Privileged Identity Management (PIM) is the primary service for managing and reducing the risks associated with privileged access. It enables just-in-time access, requires MFA for activation, enforces business justifications, and provides approval workflows, directly addressing the auditor's recommendations.
Why the other options are wrong
- A. Conditional Access can enforce MFA or device compliance, but it doesn't manage the just-in-time activation of privileged roles with justification.
- C. Access Reviews confirm existing access but don't provide JIT, MFA on activation, or justification for new role activations.
- D. Identity Protection detects risks, but doesn't manage the lifecycle and activation of privileged roles.
Microsoft Entra Privileged Identity Management (PIM)
A service that helps manage, control, and monitor access to important resources in Microsoft Entra ID, Azure, and other Microsoft Online Services, by providing just-in-time, time-bound, and approval-based access.
- Minimizes standing privileged access ('zero standing access').
- Enforces time-bound access, requiring re-activation after expiration.
- Can require MFA and business justification for role activation.
- Integrates with approval workflows for sensitive role assignments.
Memory trick: PIM guards the crown, only for a moment, then down.