AZ-500 Manage identity and access Practice Question
An organization uses Microsoft Defender for Cloud. They want to allow specific administrators to temporarily open RDP (port 3389) to a virtual machine only when needed, and for a limited time, while minimizing management overhead. Which Defender for Cloud feature should they use?
⚠ Common exam trap
Many exam-takers confuse Azure Bastion (persistent secure access) with JIT (time-limited port opening), or mistakenly think PIM controls network access rather than role activation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Just-in-time (JIT) VM access
Just-in-time (JIT) VM access in Microsoft Defender for Cloud allows administrators to temporarily open RDP (port 3389) to a virtual machine for a limited time, reducing exposure to brute-force attacks. It integrates with Azure Network Security Groups (NSGs) and Azure Firewall to automatically lock down inbound traffic when not in use, minimizing management overhead by eliminating the need for manual NSG rule changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Bastion
Why it's wrong here
Azure Bastion is a managed PaaS service that provides secure, seamless RDP/SSH connectivity to VMs directly from the Azure portal over TLS, eliminating exposure of public IPs. However, it does not provide time-limited, on-demand access control or approval workflows; it grants continuous access to any user with appropriate RBAC permissions, and lacks the ability to automatically open/close ports on a schedule or per request.
- ✓
Just-in-time (JIT) VM access
Why this is correct
Just-in-time (JIT) VM access in Microsoft Defender for Cloud dynamically creates NSG allow rules for specific ports and source IPs, and automatically removes them after the requested duration elapses (e.g., 1–3 hours). It supports approval workflows, audit logging, and integration with Microsoft Entra ID, making it the only option here that provides time-limited, on-demand access to VMs. This directly meets the stated requirement.
- ✗
Microsoft Entra Privileged Identity Management (PIM)
Why it's wrong here
Microsoft Entra Privileged Identity Management (PIM) provides time-bound, approval-based activation of privileged roles for Microsoft Entra ID and Azure resource management (control plane), such as Virtual Machine Contributor. It does not manage inbound network access to VM ports like RDP or SSH; granting a user PIM role activation allows them to manage VM settings but does not open any network-level access to the VM's OS. Therefore, PIM cannot fulfill the requirement for time-limited VM access over the network.
- ✗
Network Security Groups (NSGs)
Why it's wrong here
Network Security Groups (NSGs) filter traffic at the subnet or NIC level using prioritized allow/deny rules, but they are static configuration objects. Creating an NSG rule grants continuous access until the rule is manually removed, and NSGs themselves have no concept of time-limited, on-demand requests, approval processes, or automatic cleanup. Without an orchestration layer such as JIT VM access to dynamically manage rules, NSGs alone cannot meet the requirement.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.