A Microsoft 365 administrator is reviewing the tenant's security posture. They discover that a Global Administrator account was compromised and used to create several new user accounts. The administrator needs to identify when the Global Administrator account was activated via Privileged Identity Management (PIM) before the compromise occurred and what actions were performed. Which tool should the administrator use to gather this information?
- AMicrosoft 365 admin center - Audit log search
- BAzure AD Privileged Identity Management (PIM) audit history
- CAzure AD sign-in logs
- DMicrosoft 365 Service Health dashboard
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD Privileged Identity Management (PIM) audit history
While the Microsoft 365 Audit log search (Unified Audit Log) and Azure AD sign-in logs are useful for general activity, the Azure AD PIM audit history is specifically designed to track activations of privileged roles, including who activated a role, when, and for how long. This is the most direct and comprehensive source for information related to PIM role activations and subsequent actions performed under that activated role.
Why the other options are wrong
- A. The Unified Audit Log can show actions taken, but PIM audit history is more direct for activation details.
- C. Sign-in logs show authentication attempts, but not PIM role activations or specific actions taken under that role.
- D. Service Health provides service status, not audit information.
Azure AD PIM Audit History
The Azure AD Privileged Identity Management (PIM) audit history provides a comprehensive record of all activities related to PIM, including role activations, role assignments, and changes to PIM settings. It is crucial for security investigations and compliance auditing of privileged access.
- Records who activated a privileged role, when, and for how long.
- Tracks role assignments (eligible, active, permanent).
- Logs changes to PIM role settings and policies.
- Accessible within the PIM blade in the Azure AD admin center.
Memory trick: PIM audit history: every king's move, time, and reason.