Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium

A manufacturing company uses Azure to host its critical production control system. They need to ensure that all administrative access to Azure resources (virtual machines, databases, storage accounts) is highly secure and follows the principle of least privilege. Furthermore, they want to review and approve all elevated access requests. Which Azure service should be implemented?

  1. AAzure Security Center (now Defender for Cloud)
  2. BAzure AD Conditional Access
  3. CAzure Active Directory Identity Protection
  4. DAzure Active Directory Privileged Identity Management (PIM)
Show answer & explanation

Correct answer: D. Azure Active Directory Privileged Identity Management (PIM)

Azure AD Privileged Identity Management (PIM) allows for just-in-time (JIT) privileged access, time-bound assignments, and requires approval workflows for role activation, directly addressing the requirements for highly secure, least-privilege, and auditable administrative access.

Why the other options are wrong

  • A. Defender for Cloud provides security posture management and threat protection but doesn't directly manage privileged identity lifecycle and approvals.
  • B. Conditional Access enforces policies based on user, device, location, and application, but doesn't manage just-in-time access or approval workflows for privileged roles.
  • C. Identity Protection detects and remediates identity-based risks, but doesn't manage the lifecycle of privileged access itself.

Azure AD Privileged Identity Management (PIM)

Azure AD PIM is a service that enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft Online Services.

  • Provides just-in-time privileged access to minimize exposure time.
  • Enforces time-bound access, requiring re-activation after a set period.
  • Supports approval workflows for role activation and provides audit trails.

Memory trick: PIM: Your royal guard for temporary, approved access to the kingdom's treasures.

More Design identity, governance, and monitoring solutions questions