An organization wants to protect administrative privileges for Azure resources by enforcing just-in-time (JIT) access and requiring manager approval before roles are activated. Which of the following configurations should you include in the identity governance design? (Select TWO.)
- Configure the user assignments for the administrative roles as eligible in Microsoft Entra Privileged Identity Management (PIM).Cevap
- Enable the 'Require approval to activate' setting in the Microsoft Entra Privileged Identity Management (PIM) role settings.Cevap
- CConfigure the user assignments for the administrative roles as active with a permanent duration in Microsoft Entra Privileged Identity Management (PIM).
- DAssign the required administrative roles directly to individual user accounts at the resource subscription scope using Azure RBAC.
Cevap
Configure role assignments as eligible in Privileged Identity Management (PIM) and require activation approval in the role configurations.
To secure administrative access with just-in-time controls and approvals, the design must use Microsoft Entra Privileged Identity Management (PIM). Users should be assigned as eligible for the roles, which requires them to activate the role when needed. To implement the authorization step, the role's settings must be modified to require approval to activate.
Adım Adım Çözüm
Anahtar Kavram
Microsoft Entra Privileged Identity Management (PIM) provides time-bound and approval-based role activation to secure resources by eliminating standing access, ensuring that roles are configured as eligible and subject to approval workflows.