AZ-305 Design infrastructure solutions Practice Question
Your organization needs to provide temporary, limited-privilege access to Azure resources for external auditors. The access must be time-bound and require approval from a manager. Which Azure feature should you use?
⚠ Common exam trap
Many candidates confuse Azure RBAC roles (static assignments) with PIM's just-in-time activation, leading candidates to choose option C because they overlook the need for time-bound access and approval workflows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Privileged Identity Management (PIM)
Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by allowing time-bound activation of roles with approval workflows. This directly meets the requirement for temporary, limited-privilege access that requires manager approval, making it the correct choice for external auditor scenarios.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Managed identities
Why it's wrong here
Managed identities are Microsoft Entra ID identities automatically created for Azure resources to authenticate to services like Key Vault and Azure SQL without storing credentials. They are technical identities for application code, not for human users, and they do not offer time-bound activation, approval workflows, or temporary privilege elevation for employees. Therefore they cannot satisfy the need for temporary limited privileges.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies evaluate sign-in signals such as user location, device compliance, and risk to grant or block access to applications. While they can enforce strong authentication, they do not dynamically assign Azure RBAC roles or activate privileged roles with a time limit and approval. They control session access, not role-assignment lifecycle, so they are unsuitable for temporary limited privilege scenarios requiring approvals.
- ✗
Azure RBAC roles
Why it's wrong here
Azure RBAC roles define granular permissions for users, groups, or service principals at management groups, subscriptions, resource groups, and resources. However, role assignments remain active until manually changed; nothing in native RBAC supports automatic expiration or an approval workflow for activation. Thus, while RBAC is the underlying authorization layer, it cannot by itself provide just-in-time temporary privileges—that requires a service like PIM.
- ✓
Microsoft Entra Privileged Identity Management (PIM)
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) is the correct solution because it provides just-in-time role activation with time-bound assignments and approval-based workflows. Users become eligible for a role and activate it for a limited period by providing a justification, and if required an approver must approve the request. PIM also enforces alerts, auditing, and Multi-Factor Authentication, making it the purpose-built service for temporary limited privileged access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.