Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard

A company is implementing a Zero Trust security model in Azure. They need to configure a mechanism that automatically revokes a user's administrative role assignment after a predefined time, requiring them to re-request access. This is essential for highly privileged roles. Which Azure Active Directory feature should be used to achieve this?

  1. AAccess reviews
  2. BConditional Access policies
  3. CAzure AD Identity Protection
  4. DPrivileged Identity Management (PIM)
Show answer & explanation

Correct answer: D. Privileged Identity Management (PIM)

Azure Active Directory Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources. It supports just-in-time (JIT) access, time-bound access, and approval workflows for privileged roles, automatically revoking access after a specified duration, perfectly matching the requirement.

Why the other options are wrong

  • A. Access reviews are used to periodically review who has access to what, but they don't automate the time-bound elevation and revocation of roles.
  • B. Conditional Access policies enforce conditions (e.g., device compliance, location) *before* granting access, but don't automatically revoke roles after a time limit.
  • C. Azure AD Identity Protection detects and remediates identity-based risks (e.g., compromised credentials), but it doesn't manage time-bound role assignments.

Azure AD Privileged Identity Management (PIM)

An Azure AD feature that allows for managing, controlling, and monitoring access to important resources in Azure AD, Azure, and other Microsoft Online Services.

  • Enables just-in-time (JIT) privileged access.
  • Provides time-bound access to roles, with automatic revocation.
  • Supports approval workflows and audit trails for privileged operations.

Memory trick: PIM 'P'rotects 'I'dentity 'M'anagement with temporary keys.

More Manage security operations questions