AZ-305 Design infrastructure solutions Practice Question
Your organization has a policy that all administrative access to Azure resources must be performed using just-in-time (JIT) access. Which Azure service allows you to enable JIT VM access?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Entra Privileged Identity Management (PIM), which handles just-in-time role activation at the Azure RBAC control plane, with Defender for Cloud's JIT VM access, which handles just-in-time network-level access to VM ports at the data plane.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for Cloud
Microsoft Defender for Cloud provides just-in-time (JIT) VM access, which locks down inbound traffic to Azure VMs by creating network security group (NSG) rules that deny all inbound traffic except for specific ports. When a user requests access, Defender for Cloud temporarily creates an allow rule for the requested ports and source IP, then automatically removes it after the configured time period. This directly enforces the policy that administrative access must be JIT.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy
Why it's wrong here
Azure Policy is a governance service used to define and enforce rules on Azure resources, ensuring they remain compliant with organizational standards (e.g., tagging, allowed SKUs). It applies deny, audit, or modify effects at resource provisioning or update time, but it cannot open or close inbound network ports on demand for a specific duration, which is the core of JIT VM access. Therefore, it is incorrect for this requirement.
- ✓
Microsoft Defender for Cloud
Why this is correct
Microsoft Defender for Cloud is the correct answer because its Just-In-Time (JIT) VM access feature dynamically locks down inbound traffic to VMs using network security groups (NSGs) and opens configured ports only when an authorized user requests access for a predefined time window. The feature integrates with Microsoft Entra ID and MFA to validate requests, and then automatically restores the NSG rules to a denied state, thereby reducing brute-force and port exhaustion attack vectors.
- ✗
Microsoft Sentinel
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM and SOAR platform that aggregates logs and security telemetry from across the environment to detect, investigate, and respond to threats. It does not enforce or manage network-level access controls on VMs; its automation rules can trigger responses, but the actual JIT VM access capability is not part of Sentinel and must be delegated to Defender for Cloud.
- ✗
Microsoft Entra Privileged Identity Management
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) provides just-in-time activation for privileged identity roles in Microsoft Entra ID and Azure RBAC, such as Global Administrator or Contributor, limiting how long a user holds an elevated identity role. It does not manage or open network ports on VMs; the 'just-in-time' in PIM refers to temporary role assignments, not to time-bound network access. Thus, PIM addresses identity privilege, not VM inbound communication.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.