Microsoft Azure Fundamentals (AZ-900)Describe Azure identity, security, and networkingHard

A company is concerned about unauthorized access to its Azure resources, particularly from users with administrative privileges. They want to implement a solution that provides just-in-time (JIT) access and just-enough-access (JEA) for administrative roles, requiring approval and auditing for elevated permissions. Which Azure AD feature should they use?

  1. AAzure AD Conditional Access
  2. BAzure AD Identity Protection
  3. CAzure AD Privileged Identity Management (PIM)
  4. DAzure AD Multi-Factor Authentication (MFA)
Show answer & explanation

Correct answer: C. Azure AD Privileged Identity Management (PIM)

Azure AD Privileged Identity Management (PIM) enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft online services. It provides just-in-time, time-bound access, approval workflows, and extensive auditing capabilities for privileged roles.

Why the other options are wrong

  • A. Azure AD Conditional Access enforces access policies based on conditions, but doesn't manage JIT/JEA for privileged roles.
  • B. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not managing privileged role activation.
  • D. Azure AD MFA adds an extra layer of security to sign-ins, but doesn't manage the activation or deactivation of privileged roles.

Azure AD Privileged Identity Management (PIM)

A service that enables you to manage, control, and monitor access to important resources in Azure AD and Azure.

  • Provides just-in-time (JIT) and just-enough-access (JEA) for privileged roles.
  • Includes approval workflows for role activation.
  • Offers extensive auditing and review capabilities for privileged access.

Memory trick: PIM protects your privileged admins with JIT and JEA.

More Describe Azure identity, security, and networking questions