Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Entra IDEasy

A global manufacturing company uses Microsoft Entra ID for identity management. The company has several highly privileged roles, such as Global Administrator and Exchange Administrator, which are frequently assigned to IT personnel for short-term tasks. The security team wants to ensure that these privileged roles are only active when absolutely necessary and that their usage is audited. Which Microsoft Entra ID governance feature should you implement?

  1. AMicrosoft Entra Identity Protection
  2. BConditional Access Policies
  3. CMicrosoft Entra Privileged Identity Management (PIM)
  4. DMicrosoft Entra Access Reviews
Show answer & explanation

Correct answer: C. Microsoft Entra Privileged Identity Management (PIM)

Microsoft Entra Privileged Identity Management (PIM) allows for just-in-time (JIT) access to privileged roles. Users activate their role when needed, and access is automatically revoked after a set period, along with comprehensive auditing.

Why the other options are wrong

  • A. Identity Protection detects and remediates identity-based risks, but doesn't manage the lifecycle of privileged role assignments.
  • B. Conditional Access policies enforce conditions for access but don't manage the activation or deactivation of privileged roles themselves.
  • D. Access Reviews are for periodically verifying access, not for just-in-time role activation.

Privileged Identity Management (PIM)

Microsoft Entra Privileged Identity Management (PIM) manages, controls, and monitors access to important resources in Microsoft Entra ID, Azure, and other Microsoft Online Services. It provides just-in-time, time-bound access to privileged roles.

  • Just-in-time (JIT) access.
  • Time-bound role assignments.
  • Approval workflows and audit trails.

Memory trick: PIM: Protect Important Members

More Implement and manage Microsoft Entra ID questions