Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard
A company is implementing a zero-trust security model and needs to enforce granular access policies for administrative roles. They want to ensure that privileged users only have access to specific resources for a limited time when performing critical tasks, and their access is automatically revoked afterward. Which Azure AD PIM feature should be configured to meet this requirement?
- AAccess reviews
- BSelf-service password reset
- CJust-in-Time (JIT) access
- DConditional Access policies
Show answer & explanationAnswer & explanation
Correct answer: C. Just-in-Time (JIT) access
Just-in-Time (JIT) access, provided by Azure AD Privileged Identity Management (PIM), allows privileged roles to be activated only when needed and for a limited duration. Once the time expires, access is automatically revoked, minimizing the window of exposure for privileged accounts.
Why the other options are wrong
- A. Access reviews periodically check who has access to what, not for time-limited, on-demand access.
- B. Self-service password reset allows users to reset their own passwords, unrelated to privileged access management.
- D. Conditional Access policies enforce access controls based on conditions, but don't inherently provide time-limited, on-demand elevation of roles.
Azure AD PIM Just-in-Time Access
Azure AD Privileged Identity Management (PIM) provides Just-in-Time (JIT) access to minimize the window of exposure for privileged roles. Users activate their roles on demand, for a specific duration, and their permissions are automatically revoked when the time expires.
- Grants temporary, time-bound access to privileged roles.
- Access is activated on demand by the user.
- Automatically revokes access after the specified duration.
- Supports multi-factor authentication (MFA) for activation and approval workflows.
Memory trick: PIM gives privileged roles just enough time.