Azure Privileged Identity Management (PIM) Flashcards
Azure Privilege Identity Management (PIM)
Key features:
-Provides just-in-time privileged access to Azure AD and Azure resources
-Assigning time-bound access to resources using start and end dates.
-Requiring approval to activate privileged roles
-Enforcing MFA for role activation
-Conducting access reviews to ensure users still need roles
-Allows you to download audit history for internal and external users
-Able to send notifications
-Requires Azure AD Premium P2 license!
Implement Privileged Identity Management
- Verify your identity by using MFA
- Consent to PIM
- Sign up PIM for Azure AD roles
Which two of the following are objects you can configure to apply Azure AD PIM to?
Azure AD roles, Azure roles (for resources), or Cloud groups with the setting configured
Which roles can enable PIM and manage assignments for other admins?
Only a user who is Privileged Role Administrator or Global Administrator can manage assignments for other admins, and can ENABLE PIM
PIM assignments
Eligible: require the member to perform an action to use the role. Actions might include activation, or requesting approval.
Active: does not require the member to perform any action to use the role. Members assigned as active have the privileges assigned automatically.
PIM assignment states
Assigned: users that are assigned as active
Activated: users that activated an eligible assignment
Can users approve their own PIM request?
No, users cannot approve their own requests