Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A company wants to ensure that all administrative roles in Microsoft Entra ID are assigned with just-in-time (JIT) access and require approval for activation. This helps minimize standing access for highly privileged accounts. Which Microsoft Entra capability should they implement?
- AMicrosoft Entra Verified ID
- BMicrosoft Entra Privileged Identity Management (PIM)
- CMicrosoft Entra Access Reviews
- DMicrosoft Entra Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Entra Privileged Identity Management (PIM)
Microsoft Entra Privileged Identity Management (PIM) allows organizations to manage, control, and monitor access to important resources. This includes providing just-in-time access, requiring approval for role activation, and enforcing multi-factor authentication.
Why the other options are wrong
- A. Verified ID is for decentralized digital identities, unrelated to managing privileged roles within Microsoft Entra ID.
- C. Access Reviews help review and attest to existing access, but don't provide JIT or approval for activation.
- D. Identity Protection focuses on detecting and responding to identity-based risks, not managing privileged role assignments.
Microsoft Entra Privileged Identity Management (PIM)
A service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization. This includes access to Microsoft Entra ID, Azure, and other Microsoft Online Services.
- Provides just-in-time (JIT) privileged access.
- Enables approval workflows for role activation.
- Offers access reviews to ensure continued necessity of roles.
- Integrates with Microsoft Entra Identity Protection.
Memory trick: Govern your kingdom with Entra's wise hand.