Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard

A company is implementing a zero-trust security model and needs to enforce granular access policies for administrative roles. They want to ensure that privileged users only have access to specific resources for a limited time when performing critical tasks, and their access is automatically revoked afterward. Which Azure AD PIM feature should be configured to meet this requirement?

  1. AAccess reviews
  2. BSelf-service password reset
  3. CJust-in-Time (JIT) access
  4. DConditional Access policies
Show answer & explanation

Correct answer: C. Just-in-Time (JIT) access

Just-in-Time (JIT) access, provided by Azure AD Privileged Identity Management (PIM), allows privileged roles to be activated only when needed and for a limited duration. Once the time expires, access is automatically revoked, minimizing the window of exposure for privileged accounts.

Why the other options are wrong

  • A. Access reviews periodically check who has access to what, not for time-limited, on-demand access.
  • B. Self-service password reset allows users to reset their own passwords, unrelated to privileged access management.
  • D. Conditional Access policies enforce access controls based on conditions, but don't inherently provide time-limited, on-demand elevation of roles.

Azure AD PIM Just-in-Time Access

Azure AD Privileged Identity Management (PIM) provides Just-in-Time (JIT) access to minimize the window of exposure for privileged roles. Users activate their roles on demand, for a specific duration, and their permissions are automatically revoked when the time expires.

  • Grants temporary, time-bound access to privileged roles.
  • Access is activated on demand by the user.
  • Automatically revokes access after the specified duration.
  • Supports multi-factor authentication (MFA) for activation and approval workflows.

Memory trick: PIM gives privileged roles just enough time.

More Manage security operations questions