Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A global software development company is designing a Zero Trust strategy for its developers who frequently access source code repositories and build servers from various locations, including home offices and co-working spaces. These developers often use high-privilege accounts. The security architect needs to implement a solution that ensures these privileged accounts are only active when explicitly needed and for a limited duration, minimizing the window of opportunity for compromise. Which Zero Trust principle, specifically implemented through a solution like Azure AD PIM, is being addressed here?

  1. AVerify explicitly
  2. BSegment access
  3. CAssume breach
  4. DUse least privilege access
Show answer & explanation

Correct answer: D. Use least privilege access

The scenario describes allowing privileged accounts to be active only when needed and for a limited duration (just-in-time and just-enough access), which is the direct application of the 'Use least privilege access' principle.

Why the other options are wrong

  • A. Verify explicitly ensures continuous authentication and authorization, but 'least privilege' specifically deals with the scope and duration of those permissions.
  • B. Segment access relates to network isolation and resource grouping, not specifically the time-bound nature of user privileges.
  • C. Assume breach focuses on minimizing blast radius and improving response, not directly on limiting privilege duration.

Least Privilege Access (Zero Trust)

A core Zero Trust principle that dictates users and systems should only be granted the minimum necessary permissions to perform their tasks, and only for the minimum necessary duration.

  • Includes Just-in-Time (JIT) and Just-Enough Access (JEA).
  • Reduces the attack surface and potential damage from compromise.
  • Requires continuous monitoring and periodic review of permissions.

Memory trick: Least Privilege: Just Enough, Just In Time.

More Design a Zero Trust strategy and architecture questions