Microsoft Certified: Azure Solutions Architect ExpertDesign identity, governance, and monitoring solutionsMedium

A company is implementing a Zero Trust security model in Azure. They need to ensure that administrative access to all Azure resources is granted only when explicitly needed, for a limited time, and with full audit trails. The solution must also integrate with Azure AD roles and provide automated alerts when privileged roles are activated. Which Azure AD feature is best suited for this requirement?

  1. AAzure AD Identity Protection
  2. BAzure AD Conditional Access
  3. CAzure AD Privileged Identity Management (PIM)
  4. DAzure AD Roles and Administrators
Show answer & explanation

Correct answer: C. Azure AD Privileged Identity Management (PIM)

Azure AD Privileged Identity Management (PIM) provides just-in-time (JIT) and just-enough-access (JEA) to Azure AD and Azure resources. It enables time-bound access, approval workflows, and activation alerts, which are all critical components for implementing a Zero Trust model for administrative access and meeting the specified requirements.

Why the other options are wrong

  • A. Identity Protection focuses on detecting and preventing identity compromise, not managing just-in-time access to roles.
  • B. Conditional Access enforces policies based on conditions, but PIM is specifically for managing the lifecycle of privileged roles themselves.
  • D. Azure AD Roles and Administrators defines the static roles but doesn't provide the JIT, time-bound, or approval workflow capabilities required.

Azure AD Privileged Identity Management (PIM)

An Azure AD service that enables you to manage, control, and monitor access to important resources in your organization. It provides just-in-time (JIT) and just-enough access (JEA) to Azure AD roles and Azure resources.

  • Time-bound access for privileged roles
  • Requires approval for role activation
  • Provides auditing and alerts for role usage

Memory trick: PIM for 'Privileged Is Managed' just-in-time.

More Design identity, governance, and monitoring solutions questions