Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft EntraMedium

A financial institution requires strict control over administrative roles in Microsoft Entra ID. They want to ensure that privileged roles are assigned only when needed, for a limited time, and with proper approval workflows. Additionally, all activations of these roles must be logged for auditing purposes. Which Microsoft Entra capability is designed to meet these governance requirements?

  1. AMicrosoft Entra Access Reviews
  2. BMicrosoft Entra Privileged Identity Management (PIM)
  3. CMicrosoft Entra Identity Protection
  4. DMicrosoft Entra Conditional Access
Show answer & explanation

Correct answer: B. Microsoft Entra Privileged Identity Management (PIM)

Microsoft Entra Privileged Identity Management (PIM) is specifically designed for managing, controlling, and monitoring access to important resources. It provides just-in-time (JIT) access, time-bound assignments, approval workflows, and audit logs for privileged roles.

Why the other options are wrong

  • A. Access Reviews are for periodic re-certification of access, not for just-in-time activation or approval workflows for privileged roles.
  • C. Identity Protection focuses on detecting and remediating identity-based risks, not managing privileged role assignments.
  • D. Conditional Access enforces policies based on conditions but doesn't manage the assignment or activation lifecycle of privileged roles itself.

Microsoft Entra Privileged Identity Management (PIM)

A service in Microsoft Entra ID that enables you to manage, control, and monitor access to important resources in your organization.

  • Provides just-in-time (JIT) privileged access
  • Enforces time-bound access assignments
  • Offers approval workflows for role activation
  • Includes audit trails for all privileged role activities

Memory trick: PIM puts a crown on roles, but only for a moment.

More Describe the capabilities of Microsoft Entra questions