Microsoft Certified: Identity and Access Administrator AssociateImplement access governanceMedium
A security auditor reviews a company's Microsoft Entra ID configuration. The auditor finds that several users have been assigned the 'User Administrator' role permanently. The company's policy dictates that administrative roles should only be assigned temporarily and on a just-in-time basis. The auditor recommends implementing a solution to enforce this policy and monitor compliance. Which Microsoft Entra ID feature, when configured for the 'User Administrator' role, will provide an audit trail of role activations and automatically remove permanent assignments?
- AMicrosoft Entra Conditional Access
- BMicrosoft Entra Privileged Identity Management (PIM)
- CMicrosoft Entra Identity Protection
- DMicrosoft Entra access reviews
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Entra Privileged Identity Management (PIM)
Privileged Identity Management (PIM) is specifically designed to manage, control, and monitor access to privileged roles. It allows for just-in-time activation, enforces temporary assignments, and provides an audit trail of all role activations, while also being capable of removing permanent assignments.
Why the other options are wrong
- A. Conditional Access enforces policies during sign-in but does not manage the lifecycle of privileged role assignments or provide an audit trail of role activations.
- C. Identity Protection focuses on detecting and remediating identity-based risks, not on enforcing just-in-time privileged role assignments or providing an audit trail of role activations.
- D. Access reviews periodically verify existing access but do not enforce just-in-time activation or directly remove permanent assignments for privileged roles; PIM has its own access review capabilities for this.
PIM for Privileged Roles
Microsoft Entra Privileged Identity Management (PIM) provides time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions.
- Enforces just-in-time (JIT) and just-enough access.
- Provides an audit trail of role activations and usage.
- Can convert permanent assignments to eligible or remove them after a grace period.
Memory trick: PIM is the 'privileged access gatekeeper' with a detailed logbook.