Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureEasy
A company is implementing a Zero Trust strategy and needs to establish a robust identity governance framework. They want to ensure that privileged access is granted only when necessary, for a limited time, and with proper approval workflows. This approach should also include automated deactivation of elevated privileges after a specific period. Which Azure AD capability is designed to address these requirements?
- AAzure AD Identity Protection
- BAzure AD Access Reviews
- CAzure AD Conditional Access
- DAzure AD Privileged Identity Management (PIM)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Privileged Identity Management (PIM)
Azure AD Privileged Identity Management (PIM) provides just-in-time (JIT) and just-enough-access (JEA) for Azure AD roles and Azure resources. It includes approval workflows, time-bound activation, and automated deactivation of privileges, directly aligning with the requirements for robust identity governance of privileged access.
Why the other options are wrong
- A. Identity Protection detects and remediates identity-based risks, not privileged access management workflows.
- B. Access Reviews help manage group memberships and access to applications but don't provide JIT/JEA for privileged roles.
- C. Conditional Access enforces policies based on conditions but doesn't manage time-bound privileged role activation.
Azure AD Privileged Identity Management (PIM)
An Azure AD service that enables management, control, and monitoring of access to important resources in Azure AD, Azure, and other Microsoft Online Services.
- Provides Just-In-Time (JIT) access to privileged roles.
- Enforces Just-Enough-Access (JEA) principles.
- Includes approval workflows for role activation.
- Automates deactivation of privileges after a set time.
Memory trick: PIM: Privileged, In-time, Managed.