Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium
A financial institution requires strict control over administrative roles in Microsoft Entra ID. They want to ensure that privileged roles are assigned only when needed, for a limited time, and with proper approval workflows. Additionally, all activations of these roles must be logged for auditing purposes. Which Microsoft Entra capability is designed to meet these governance requirements?
- AMicrosoft Entra Access Reviews
- BMicrosoft Entra Privileged Identity Management (PIM)
- CMicrosoft Entra Identity Protection
- DMicrosoft Entra Conditional Access
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Entra Privileged Identity Management (PIM)
Microsoft Entra Privileged Identity Management (PIM) is specifically designed for managing, controlling, and monitoring access to important resources. It provides just-in-time (JIT) access, time-bound assignments, approval workflows, and audit logs for privileged roles.
Why the other options are wrong
- A. Access Reviews are for periodic re-certification of access, not for just-in-time activation or approval workflows for privileged roles.
- C. Identity Protection focuses on detecting and remediating identity-based risks, not managing privileged role assignments.
- D. Conditional Access enforces policies based on conditions but doesn't manage the assignment or activation lifecycle of privileged roles itself.
Microsoft Entra Privileged Identity Management (PIM)
A service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization.
- Provides just-in-time (JIT) privileged access
- Enforces time-bound access assignments
- Offers approval workflows for role activation
- Includes audit trails for all privileged role activities
Memory trick: PIM puts a crown on roles, but only for a moment.