What's changed: Created SC-300 Chapter 5 (Domain 4: entitlement management (catalogs/access packages/policies/My Access/connected organizations/ToU/external lifecycle); access reviews (scope/reviewers/auto-apply/privileged-role reviews); PIM (eligible/active/activation/Entra roles/Azure resources/PIM for Groups/settings/audit history/break-glass); monitoring (sign-in/audit/provisioning logs/diagnostic settings Log Analytics-storage-Event Hubs/KQL/workbooks/Identity Secure Score)).
5.3Privileged Identity Management (PIM)
Understand Just-In-Time elevation of Entra roles/Azure resources/groups with Microsoft Entra Privileged Identity Management (PIM), request/approval, settings (MFA, justification, expiry), audit history, and break-glass accounts.
Privilege is the biggest attack target. Privileged Identity Management (PIM) changes admin roles from "standing assignment" to "elevate only when needed," enforcing least privilege over time.
5.3.1Just-In-Time elevation and scope
In PIM, assign users to roles as eligible rather than active (standing). Eligible users activate only when needed, elevating time-bound with auto-expiry. Scope covers Entra roles, Azure resource roles (RBAC), and PIM for Groups (JIT for group membership/ownership—so even group-based access becomes time-bound). "Five standing Global Administrators" is resolved by making them eligible + reducing the count.
5.3.2Settings, approval, audit, and break-glass
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

