Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard
A regulated financial institution uses Azure AD and has a strict requirement to ensure that all administrative access to Azure resources (subscriptions, resource groups) is logged, approved, and time-limited. They also need to ensure that administrators only have elevated privileges when absolutely necessary. Which combination of Azure AD features should be implemented?
- AAzure AD B2B Collaboration and Managed Identities
- BAzure AD Conditional Access and Administrative Units
- CAzure AD Custom Roles and Azure AD Identity Protection
- DAzure AD PIM for Azure resources and Azure AD Audit logs
Show answer & explanationAnswer & explanation
Correct answer: D. Azure AD PIM for Azure resources and Azure AD Audit logs
Azure AD PIM for Azure resources allows for just-in-time, time-limited, and approval-based elevation of access to Azure subscriptions and resource groups, directly addressing 'time-limited' and 'approved' elevated privileges. Azure AD Audit logs then provide the 'logged' aspect for all these administrative actions.
Why the other options are wrong
- A. B2B Collaboration is for external users, and Managed Identities are for Azure resources to authenticate, neither addresses the core requirement.
- B. Conditional Access enforces policies during sign-in, and Administrative Units delegate control over AD objects, neither directly addresses time-limited, approved, and logged elevation for Azure resources.
- C. Custom Roles define permissions, but don't inherently provide time-limited, approved, or logged elevation. Identity Protection focuses on risk, not privileged access management.
Azure AD PIM for Azure Resources
A feature of Azure AD PIM that extends just-in-time, time-limited, and approval-based access to Azure RBAC roles for subscriptions, resource groups, and resources.
- Elevates access to Azure RBAC roles.
- Enforces time limits and approval workflows.
- Integrates with Azure AD Audit logs for logging.
Memory trick: PIM for Azure resources is like a secure vault for your admin powers, with an audit trail.