Microsoft Certified: Azure Security Engineer AssociateManage identity and accessEasy
A global enterprise is implementing a new policy for managing administrative access to Azure subscriptions. They want to ensure that 'Global Administrator' roles are never permanently assigned to any user. Instead, administrators should be able to request elevated privileges for a limited time and with justification. Which Azure AD feature should be configured to meet this requirement?
- AAzure AD Conditional Access
- BAzure AD Privileged Identity Management (PIM)
- CAzure AD Access Reviews
- DAzure AD Identity Protection
Show answer & explanationAnswer & explanation
Correct answer: B. Azure AD Privileged Identity Management (PIM)
Azure AD Privileged Identity Management (PIM) allows organizations to manage, control, and monitor access to important resources. It enables just-in-time (JIT) access to privileged roles, requiring users to activate the role for a limited time and provide a justification, thus preventing standing access to highly sensitive roles like Global Administrator.
Why the other options are wrong
- A. Conditional Access enforces policies based on conditions, but doesn't manage the activation of privileged roles.
- C. Access Reviews are for periodically verifying existing access, not for granting temporary elevated privileges with justification.
- D. Identity Protection focuses on detecting and remediating identity-based risks, not managing just-in-time role assignments.
Azure AD Privileged Identity Management (PIM)
A service that enables you to manage, control, and monitor access to important resources in Azure AD, Azure, and other Microsoft online services.
- Provides just-in-time (JIT) access.
- Requires activation and justification for roles.
- Enforces time-bound access.
Memory trick: PIM: Privileged, In-time, Managed.