Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium
A global software development company is designing a Zero Trust strategy for its developers who frequently access source code repositories and build servers from various locations, including home offices and co-working spaces. These developers often use high-privilege accounts. The security architect needs to implement a solution that ensures these privileged accounts are only active when explicitly needed and for a limited duration, minimizing the window of opportunity for compromise. Which Zero Trust principle, specifically implemented through a solution like Azure AD PIM, is being addressed here?
- AVerify explicitly
- BSegment access
- CAssume breach
- DUse least privilege access
Show answer & explanationAnswer & explanation
Correct answer: D. Use least privilege access
The scenario describes allowing privileged accounts to be active only when needed and for a limited duration (just-in-time and just-enough access), which is the direct application of the 'Use least privilege access' principle.
Why the other options are wrong
- A. Verify explicitly ensures continuous authentication and authorization, but 'least privilege' specifically deals with the scope and duration of those permissions.
- B. Segment access relates to network isolation and resource grouping, not specifically the time-bound nature of user privileges.
- C. Assume breach focuses on minimizing blast radius and improving response, not directly on limiting privilege duration.
Least Privilege Access (Zero Trust)
A core Zero Trust principle that dictates users and systems should only be granted the minimum necessary permissions to perform their tasks, and only for the minimum necessary duration.
- Includes Just-in-Time (JIT) and Just-Enough Access (JEA).
- Reduces the attack surface and potential damage from compromise.
- Requires continuous monitoring and periodic review of permissions.
Memory trick: Least Privilege: Just Enough, Just In Time.