Azure Privileged Identity Management (PIM) Flashcards

1
Q

Azure Privilege Identity Management (PIM)

A

Key features:
-Provides just-in-time privileged access to Azure AD and Azure resources
-Assigning time-bound access to resources using start and end dates.
-Requiring approval to activate privileged roles
-Enforcing MFA for role activation
-Conducting access reviews to ensure users still need roles
-Allows you to download audit history for internal and external users
-Able to send notifications
-Requires Azure AD Premium P2 license!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Implement Privileged Identity Management

A
  1. Verify your identity by using MFA
  2. Consent to PIM
  3. Sign up PIM for Azure AD roles
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which two of the following are objects you can configure to apply Azure AD PIM to?

A

Azure AD roles, Azure roles (for resources), or Cloud groups with the setting configured

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which roles can enable PIM and manage assignments for other admins?

A

Only a user who is Privileged Role Administrator or Global Administrator can manage assignments for other admins, and can ENABLE PIM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PIM assignments

A

Eligible: require the member to perform an action to use the role. Actions might include activation, or requesting approval.

Active: does not require the member to perform any action to use the role. Members assigned as active have the privileges assigned automatically.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

PIM assignment states

A

Assigned: users that are assigned as active

Activated: users that activated an eligible assignment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Can users approve their own PIM request?

A

No, users cannot approve their own requests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly