198k views
2 votes
You want the ability to elevate a user's account to that of a temporary administrator. Which Microsoft 365 identity management feature could help with this?

a) Azure Active Directory (Azure AD) Privileged Identity Management (PIM)
b) Azure AD External Identities
c) Azure AD B2B collaboration
d) Azure AD Connect

User Handhand
by
7.4k points

1 Answer

3 votes

Final answer:

Azure Active Directory (Azure AD) Privileged Identity Management (PIM) is the Microsoft 365 feature that allows elevating a user's account to a temporary administrator. It provides just-in-time privileged access that is time-bound and can require approval, thereby enhancing security by adhering to the principle of least privilege.

Step-by-step explanation:

The feature that would allow you to elevate a user's account to that of a temporary administrator in Microsoft 365 is Azure Active Directory (Azure AD) Privileged Identity Management (PIM). Azure AD PIM allows an organization to manage, control, and monitor access within Azure AD, Azure, and other Microsoft Online Services. With Azure AD PIM, you can assign time-bound access to resources using start and end dates, require approval to activate privileged roles, enforce multi-factor authentication to activate any role, and use justification to understand why users activate.

When a user needs to perform tasks that require elevated permissions, Azure AD PIM provides a way to give these permissions on a just-in-time basis, significantly reducing the risks associated with permanent administrative access. After the specified period, the user's elevated permissions are automatically revoked, ensuring an adherence to the principle of least privilege.

User Nnseva
by
7.9k points