Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy
A company wants to ensure that all administrative roles within Microsoft Entra ID are assigned just-in-time and with time limits. Which Microsoft Entra capability should they implement?
- AMicrosoft Entra Identity Protection
- BMicrosoft Entra Privileged Identity Management (PIM)
- CMicrosoft Entra Conditional Access
- DMicrosoft Entra Access Reviews
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Entra Privileged Identity Management (PIM)
Microsoft Entra Privileged Identity Management (PIM) allows for just-in-time and time-bound access to privileged roles, reducing the attack surface for standing administrative permissions.
Why the other options are wrong
- A. Identity Protection detects and remediates identity-based risks, not for managing privileged role assignments.
- C. Conditional Access manages access based on conditions, but doesn't provide just-in-time role assignment.
- D. Access Reviews are for periodically reviewing existing access, not for just-in-time provisioning.
Microsoft Entra Privileged Identity Management (PIM)
A service that enables you to manage, control, and monitor access to important resources in Microsoft Entra ID, Azure, and other Microsoft Online Services.
- Provides just-in-time (JIT) access to roles.
- Enforces time-bound access.
- Requires approval for role activation.
Memory trick: PIM protects the crown with a time-locked key.