Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A regulated financial institution uses Azure AD and has a strict requirement to ensure that all administrative access to Azure resources (subscriptions, resource groups) is logged, approved, and time-limited. They also need to ensure that administrators only have elevated privileges when absolutely necessary. Which combination of Azure AD features should be implemented?

  1. AAzure AD B2B Collaboration and Managed Identities
  2. BAzure AD Conditional Access and Administrative Units
  3. CAzure AD Custom Roles and Azure AD Identity Protection
  4. DAzure AD PIM for Azure resources and Azure AD Audit logs
Show answer & explanation

Correct answer: D. Azure AD PIM for Azure resources and Azure AD Audit logs

Azure AD PIM for Azure resources allows for just-in-time, time-limited, and approval-based elevation of access to Azure subscriptions and resource groups, directly addressing 'time-limited' and 'approved' elevated privileges. Azure AD Audit logs then provide the 'logged' aspect for all these administrative actions.

Why the other options are wrong

  • A. B2B Collaboration is for external users, and Managed Identities are for Azure resources to authenticate, neither addresses the core requirement.
  • B. Conditional Access enforces policies during sign-in, and Administrative Units delegate control over AD objects, neither directly addresses time-limited, approved, and logged elevation for Azure resources.
  • C. Custom Roles define permissions, but don't inherently provide time-limited, approved, or logged elevation. Identity Protection focuses on risk, not privileged access management.

Azure AD PIM for Azure Resources

A feature of Azure AD PIM that extends just-in-time, time-limited, and approval-based access to Azure RBAC roles for subscriptions, resource groups, and resources.

  • Elevates access to Azure RBAC roles.
  • Enforces time limits and approval workflows.
  • Integrates with Azure AD Audit logs for logging.

Memory trick: PIM for Azure resources is like a secure vault for your admin powers, with an audit trail.

More Manage identity and access questions