Your company deploys Microsoft Sentinel for security operations. You need to configure just-in-time (JIT) access for Azure VMs. Which Azure security feature should you integrate with Sentinel?
Microsoft Defender for Cloud is the correct choice because it directly provides just-in-time (JIT) VM access, a feature that locks down inbound traffic to virtual machines and opens designated ports only when requested and approved. This integration sends activity data to Microsoft Sentinel for advanced threat detection and response, making it the service that operationalizes JIT for security operations.
Why this answer
Microsoft Defender for Cloud provides the just-in-time (JIT) VM access capability, which can be integrated with Microsoft Sentinel to enable automated threat response. When a security incident is detected in Sentinel, a playbook can trigger Defender for Cloud to lock down or open specific ports (e.g., RDP 3389, SSH 22) for a defined time window, reducing the attack surface. This integration relies on the Defender for Cloud's JIT policy applied at the subscription or VM level, not on external network controls or identity governance.
Exam trap
The trap here is that candidates confuse just-in-time network access (JIT VM access) with just-in-time privileged role activation (PIM), because both use the term 'just-in-time' but operate at completely different layers—network vs. identity.
How to eliminate wrong answers
Option B (Azure Policy) is wrong because Azure Policy enforces compliance rules (e.g., requiring JIT to be enabled) but does not itself grant or manage time-bound network access; it is a governance tool, not an access control mechanism. Option C (Azure Firewall) is wrong because Azure Firewall is a managed network firewall that filters traffic at the perimeter, but JIT access is a VM-level network security group (NSG) feature that dynamically modifies NSG rules, not a firewall rule. Option D (Microsoft Entra Privileged Identity Management) is wrong because PIM manages just-in-time privileged role activation for Azure AD roles and Azure resource roles (e.g., Contributor), not network-level access to VM ports; it controls who can administer resources, not how traffic reaches the VM.