A global company needs to manage access to its Azure resources, ensuring that users only have the minimum necessary permissions to perform their job functions. They also want to periodically review and grant temporary elevated access for administrators when required. Which Azure identity and access management service should they use to achieve this?
- AAzure AD Identity Protection
- BRole-Based Access Control (RBAC)
- CAzure Active Directory (Azure AD)
- DAzure Active Directory Privileged Identity Management (PIM)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Active Directory Privileged Identity Management (PIM)
Azure AD Privileged Identity Management (PIM) allows you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft online services. It includes capabilities for just-in-time (JIT) access, access reviews, and activation of eligible roles, which perfectly addresses the need for temporary elevated access and periodic reviews.
Why the other options are wrong
- A. Azure AD Identity Protection detects and remediates identity-based risks.
- B. RBAC defines specific permissions, but PIM manages *how* and *when* those roles are granted, especially for privileged ones.
- C. Azure Active Directory is the foundational identity service, but PIM provides advanced capabilities for privileged access.
Azure AD Privileged Identity Management (PIM)
Azure AD Privileged Identity Management (PIM) is a service in Azure AD that enables you to manage, control, and monitor access to important resources, providing just-in-time access and role activation.
- Provides just-in-time (JIT) access to roles
- Enforces approval workflows for role activation
- Supports access reviews for privileged roles
- Monitors privileged access and provides audit logs
Memory trick: PIM is the royal guard for your most powerful roles, ensuring access is temporary and reviewed.