Least-Privilege Identity Strategy: Managed Identities and PIM
Which TWO actions should you take to implement a least-privilege identity strategy for Azure resources?
Quick Answer
The correct answer is to use Privileged Identity Management (PIM) to activate roles just-in-time and to use managed identities for Azure resources. PIM enforces least-privilege by requiring time-bound, approved role activation, eliminating standing admin access, while managed identities remove the need for stored credentials by allowing Azure resources to authenticate directly to Azure AD via the Instance Metadata Service (IMDS) without any secrets. On the AZ-305 exam, this pairing tests your understanding of identity governance versus credential management—a common trap is to confuse PIM with permanent role assignments or to overlook that managed identities replace service principals with static secrets. Remember the mnemonic: “PIM for time, MI for no crime”—PIM controls when you have access, and Managed Identities eliminate the risk of credential theft.
⚠ Common exam trap
Candidates often confuse storing secrets securely (Option B) with eliminating secrets entirely (Option D), or they overlook that PIM (Option E) is a core least-privilege tool for role activation, not just a monitoring feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use managed identities for Azure resources instead of service principals
Managed identities for Azure resources eliminate the need to store and manage credentials. Azure automatically rotates the identity's principal in Azure AD, and the resource can obtain an access token directly from the Azure Instance Metadata Service (IMDS) endpoint without any secrets. This aligns with the least-privilege principle by removing static, long-lived credentials and reducing the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign Global Administrator role to all cloud architects
Why it's wrong here
Global Admin is highly privileged, violates least privilege.
- ✗
Store service principal passwords in Azure Key Vault and retrieve at runtime
Why it's wrong here
Using certificates or managed identities is better.
- ✗
Enable self-service password reset for all users
Why it's wrong here
SSPR is about password management, not least privilege.
- ✓
Use managed identities for Azure resources instead of service principals
Why this is correct
Managed identities remove the need to manage secrets.
- ✓
Use Privileged Identity Management (PIM) to activate roles just-in-time
Why this is correct
PIM reduces standing access.
Go deeper
Related to this question
About these practice questions
One of 212 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-305
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions should you take to implement a least-privilege identity strategy for Azure resources?
medium- ✓ A.Use managed identities for Azure resources instead of service principals with secrets
- B.Assign the Contributor role at the subscription scope to allow flexibility
- C.Use storage account keys for access to blob data
- ✓ D.Enable Privileged Identity Management (PIM) for just-in-time role assignments
- E.Use a single service principal for all applications
Why A: Managed identities for Azure resources eliminate the need to manage credentials by automatically rotating them and binding them to a resource lifecycle. This removes the risk of secret leakage or mismanagement that exists with service principal secrets, directly supporting a least-privilege identity strategy by ensuring identities are scoped and ephemeral.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.