SC-900 Describe the capabilities of Microsoft Entra Practice Question
A company wants to reduce the risk of privileged account misuse. They need to provide temporary, time-bound access to administrative roles in Microsoft Entra ID (Microsoft Entra ID) and require approval from a manager before granting the access. Which Microsoft Entra capability should they use?
⚠ Common exam trap
Watch out — candidates often confuse PIM with Conditional Access or Access Reviews, mistakenly thinking those services can enforce time-bound approvals, but only PIM combines JIT activation with an approval workflow for privileged roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Privileged Identity Management (PIM)
Microsoft Entra Privileged Identity Management (PIM) provides just-in-time (JIT) privileged access by allowing administrators to activate roles for a limited, time-bound duration. It also supports approval workflows, requiring a manager's approval before role activation is granted, directly addressing the need for temporary, approved access to administrative roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditional Access policies
Why it's wrong here
Conditional Access policies are designed to enforce specific conditions for accessing resources, such as requiring a compliant device, a trusted location, or multi-factor authentication. While crucial for overall security posture by evaluating existing access requests against predefined rules, they do not provide mechanisms for managing the activation of privileged roles. Conditional Access does not offer just-in-time role elevation, time-bound access, or approval workflows for temporary privilege grants.
- ✓
Microsoft Entra Privileged Identity Management (PIM)
Why this is correct
Microsoft Entra Privileged Identity Management (PIM) directly addresses the risk of privileged account misuse by implementing just-in-time (JIT) access. It enables users to activate privileged roles only when needed, for a limited duration, and often requires an explicit approval workflow before elevation. This significantly reduces the attack surface by eliminating standing privileged access and provides comprehensive auditing of all privilege activations.
- ✗
Identity Protection
Why it's wrong here
Identity Protection focuses on detecting and remediating identity-based risks, such as compromised credentials, risky sign-ins from unusual locations, or malware-infected devices. Its primary function is to identify suspicious activity related to user accounts and enforce automated remediation actions like password resets or multi-factor authentication challenges. However, it does not provide capabilities for managing the lifecycle of privileged role assignments, including time-bound activation or approval processes.
- ✗
Entra ID Governance (Access Reviews)
Why it's wrong here
Entra ID Governance Access Reviews are a critical component for periodically evaluating and recertifying existing user access rights to groups, applications, and roles. They help ensure that users retain only the access necessary for their job functions by prompting reviewers to confirm or remove permissions. While essential for maintaining a least-privilege environment over time, Access Reviews do not offer an on-demand system for requesting, approving, and activating temporary, time-limited privileged roles.
Go deeper
Related to this question
Learn chapter
Identity Concepts
Key term
PIM
Privileged Identity Management, a Microsoft Azure Active Directory tool that manages, monitors, and controls access to privileged roles on a just-in-time basis.
Key term
Privileged Identity Management
Privileged Identity Management is a security system that controls, monitors, and audits access to sensitive systems by granting elevated permissions only when needed and for a limited time.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.