Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium

A global logistics company uses Azure for its critical order fulfillment system. They need to implement a solution that allows specific users to elevate their privileges for a limited time to perform administrative tasks, such as modifying critical Azure resources. After the time limit, the privileges should automatically revert. All elevations must be auditable. Which Azure service should be used?

  1. AAzure AD Conditional Access
  2. BAzure Active Directory Identity Protection
  3. CAzure Security Center (Defender for Cloud)
  4. DAzure Active Directory Privileged Identity Management (PIM)
Show answer & explanation

Correct answer: D. Azure Active Directory Privileged Identity Management (PIM)

Azure Active Directory Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources. It provides just-in-time (JIT) access, time-bound access, and requires approval or multi-factor authentication for role activation, all with comprehensive auditing, directly meeting the requirements for temporary privilege elevation.

Why the other options are wrong

  • A. Conditional Access enforces access policies based on conditions but doesn't manage time-bound or just-in-time privilege elevation.
  • B. Identity Protection detects and remediates identity-based risks, not for managing temporary privilege elevation.
  • C. Security Center (Defender for Cloud) focuses on security posture management and threat protection, not privilege elevation.

Azure AD PIM

Azure Active Directory Privileged Identity Management (PIM) is a service that enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft services.

  • Provides just-in-time (JIT) and time-bound access to roles.
  • Requires activation (e.g., MFA, approval) for privileged roles.
  • Offers auditing and review capabilities for privileged access.

Memory trick: PIM: The temporary key that locks itself after use.

More Design identity, governance, and monitoring solutions questions