Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A financial services company is concerned about unauthorized access to highly sensitive data by administrators. They want to implement a solution that grants administrators just-in-time (JIT) access to specific Azure resources and requires approval for these elevated privileges. The solution should also provide auditing and review capabilities for all privilege activations. Which Azure AD feature should be implemented?
- AAzure AD Identity Protection
- BAzure AD Roles and Administrators
- CAzure AD Conditional Access
- DAzure AD Privileged Identity Management (PIM)
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD Privileged Identity Management (PIM)
Azure AD Privileged Identity Management (PIM) allows for just-in-time (JIT) access to Azure resources, requiring activation and approval for elevated roles, and provides auditing for these activities.
Why the other options are wrong
- A. Azure AD Identity Protection focuses on detecting and remediating identity-based risks, not managing JIT privileged access.
- B. Azure AD Roles and Administrators defines static roles, but doesn't provide JIT access or activation workflows.
- C. Azure AD Conditional Access enforces access policies based on conditions, but doesn't manage JIT activation of roles.
Azure AD PIM
A service in Azure Active Directory that enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft Online Services.
- Provides just-in-time (JIT) access to roles.
- Requires activation for privileged roles, often with approval workflows.
- Includes auditing, access reviews, and alerts for privileged activities.
Memory trick: Give kings temporary crowns, not permanent ones.