Microsoft Certified: Identity and Access Administrator AssociateImplement and manage workload identitiesHard

A company uses Azure DevOps for its CI/CD pipelines. These pipelines need to frequently update Azure resource tags, which requires the 'Contributor' role on resource groups. To enhance security, the company wants to ensure that the service principal used by Azure DevOps only has elevated permissions during the brief period of deployment and automatically reverts to minimal permissions afterward. Which Azure AD feature, in conjunction with an Azure AD service principal, would best meet this requirement?

  1. AAzure AD Identity Protection.
  2. BAzure AD Conditional Access.
  3. CAzure AD Privileged Identity Management (PIM).
  4. DAzure AD Access Reviews.
Show answer & explanation

Correct answer: C. Azure AD Privileged Identity Management (PIM).

Azure AD Privileged Identity Management (PIM) allows for just-in-time (JIT) access to Azure AD roles and Azure resources. While primarily for human identities, PIM can also be used to manage access for service principals (workload identities) to ensure they only have elevated permissions when actively needed.

Why the other options are wrong

  • A. Identity Protection detects and remediates identity-based risks for users, not for managing temporary elevated permissions for service principals.
  • B. Conditional Access policies enforce access controls based on conditions but don't manage time-bound elevation of permissions for service principals.
  • D. Access Reviews help manage lifecycle of access rights by periodic review, but they don't provide just-in-time elevation for deployments.

PIM for Workload Identities

Extending Azure AD Privileged Identity Management (PIM) to manage just-in-time (JIT) access for service principals (workload identities) to Azure AD roles or Azure resource roles, enabling time-bound and approved elevated permissions.

  • Provides just-in-time (JIT) access.
  • Can be configured for service principals (application registrations).
  • Enhances security by limiting exposure of high-privilege roles.

Memory trick: PIM for Workloads: Just-in-time, like a temporary key, security's prime.

More Implement and manage workload identities questions