Instiq
Chapter 5 · Identity governance and monitoring·v1.0.0·Updated 6/29/2026·~14 min

What's changed: Created SC-300 Chapter 5 (Domain 4: entitlement management (catalogs/access packages/policies/My Access/connected organizations/ToU/external lifecycle); access reviews (scope/reviewers/auto-apply/privileged-role reviews); PIM (eligible/active/activation/Entra roles/Azure resources/PIM for Groups/settings/audit history/break-glass); monitoring (sign-in/audit/provisioning logs/diagnostic settings Log Analytics-storage-Event Hubs/KQL/workbooks/Identity Secure Score)).

5.3Privileged Identity Management (PIM)

Key points

Understand Just-In-Time elevation of Entra roles/Azure resources/groups with Microsoft Entra Privileged Identity Management (PIM), request/approval, settings (MFA, justification, expiry), audit history, and break-glass accounts.

Privilege is the biggest attack target. Privileged Identity Management (PIM) changes admin roles from "standing assignment" to "elevate only when needed," enforcing least privilege over time.

5.3.1Just-In-Time elevation and scope

In PIM, assign users to roles as eligible rather than active (standing). Eligible users activate only when needed, elevating time-bound with auto-expiry. Scope covers Entra roles, Azure resource roles (RBAC), and PIM for Groups (JIT for group membership/ownership—so even group-based access becomes time-bound). "Five standing Global Administrators" is resolved by making them eligible + reducing the count.

5.3.2Settings, approval, audit, and break-glass

Define activation settings per role: require MFA, justification, ticket number, approver approval, and maximum duration. This records "who elevated, when, and why," traceable via PIM audit history/reports. Because PIM and CA tightening everything could lock everyone out in an emergency, prepare two or more break-glass accounts excluded from PIM/CA, with strong protection (long password, physical storage, monitoring). This reconciles "strict least privilege" with "avoiding lockout."

Exam point

Cues: "no standing admin role; elevate only when needed with approval/MFA/expiry" = PIM eligible + activate. "JIT for group-based access too" = PIM for Groups. "JIT for Azure resource permissions" = PIM Azure resource roles. "who elevated when and why" = PIM audit history. "avoid locking everyone out" = exclude break-glass from PIM/CA.

Warning

Watch the mix-ups: (1) Eligible (activate when needed) vs active (standing). (2) PIM is JIT privilege elevation—different from reducing multicloud over-permissions (Permissions Management/CIEM). (3) Break-glass is excluded from PIM/CA but must still have strong protection and monitoring.

Diagram of eligible → activate (JIT elevation with MFA/justification/approval/expiry), scope of Entra roles/Azure resources/PIM for Groups, audit history, and break-glass excluded from PIM/CA.
No standing grants

5.3.3Section summary

  • PIM = make roles eligible, activate only when needed (MFA/justification/approval/expiry); scope = Entra roles/Azure resources/PIM for Groups
  • Track elevation via audit history; prepare break-glass excluded from PIM/CA with strong protection (avoid lockout)
  • Distinguish eligible (when needed) from active (standing); PIM (JIT elevation) differs from CIEM (reducing over-permissions)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want admin roles not standing—elevated only when needed with MFA, approval, and expiry, then auto-revoked. Which is best?

Q2. You want group membership (group-based access) to be active only when needed, time-bound. Which is best?

Q3. You want to prevent all admins being locked out in an emergency after PIM/CA tighten everything. Which is best?

Q4. Which correctly distinguishes PIM eligible from active assignment?

Q5. You want to track "when/who/why a privileged role was elevated" and report for compliance. Which is best?

Check your understandingPractice questions for Chapter 5: Identity governance and monitoring

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.