Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium

A financial institution uses Azure AD and is implementing a new policy for highly privileged administrative roles. To mitigate the risk of standing access and credential compromise, they require that all assignments for Global Administrator and Application Administrator roles are time-bound and require multi-factor authentication (MFA) and approval before activation. Which Azure AD feature is specifically designed to enforce these requirements?

  1. AAzure AD Role-Based Access Control (RBAC)
  2. BAzure AD Privileged Identity Management (PIM)
  3. CAzure AD Conditional Access
  4. DAzure AD Identity Protection
Show answer & explanation

Correct answer: B. Azure AD Privileged Identity Management (PIM)

Azure AD Privileged Identity Management (PIM) is designed to manage, control, and monitor access to important resources. It provides just-in-time (JIT) access, time-bound assignments, approval workflows, and MFA enforcement for role activation, directly addressing all the stated requirements for privileged roles.

Why the other options are wrong

  • A. Azure AD RBAC defines who has what permissions, but doesn't manage just-in-time access or activation workflows.
  • C. Conditional Access can enforce MFA but does not provide time-bound role assignments or activation workflows for roles.
  • D. Identity Protection focuses on risk detection and remediation, not on managing privileged role assignments directly.

Azure AD Privileged Identity Management (PIM)

A service in Azure AD that enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft Online Services.

  • Provides just-in-time (JIT) privileged access.
  • Enforces time-bound access and approval workflows.
  • Integrates with Azure AD roles and Azure resources roles.

Memory trick: PIM ensures privileged access is Just-In-Time and approved.

More Manage identity and access questions