Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraEasy

A company wants to ensure that all administrative roles within Microsoft Entra ID are assigned just-in-time and with time limits. Which Microsoft Entra capability should they implement?

  1. AMicrosoft Entra Identity Protection
  2. BMicrosoft Entra Privileged Identity Management (PIM)
  3. CMicrosoft Entra Conditional Access
  4. DMicrosoft Entra Access Reviews
Show answer & explanation

Correct answer: B. Microsoft Entra Privileged Identity Management (PIM)

Microsoft Entra Privileged Identity Management (PIM) allows for just-in-time and time-bound access to privileged roles, reducing the attack surface for standing administrative permissions.

Why the other options are wrong

  • A. Identity Protection detects and remediates identity-based risks, not for managing privileged role assignments.
  • C. Conditional Access manages access based on conditions, but doesn't provide just-in-time role assignment.
  • D. Access Reviews are for periodically reviewing existing access, not for just-in-time provisioning.

Microsoft Entra Privileged Identity Management (PIM)

A service that enables you to manage, control, and monitor access to important resources in Microsoft Entra ID, Azure, and other Microsoft Online Services.

  • Provides just-in-time (JIT) access to roles.
  • Enforces time-bound access.
  • Requires approval for role activation.

Memory trick: PIM protects the crown with a time-locked key.

More Describe the capabilities of Microsoft Entra questions