Microsoft Azure Solutions Architect Expert AZ-305 Practice Question
Your company hires external vendors to apply monthly security patches in several Azure subscriptions. Security policy states that vendors cannot have standing permissions, can activate permissions only during the approved maintenance window for no more than eight hours, must obtain approval from the subscription owner for each activation, and all activation activity must be automatically audited without custom scripts. With minimal administrative effort, which Azure-native solution satisfies all requirements?
Configure Azure AD Privileged Identity Management and assign vendors as eligible for the required Azure RBAC role.
Apply an Azure Policy initiative that blocks role actions outside the maintenance window.
Create an access package in Azure AD entitlement management that adds vendors to the required role.
Assign vendors to a custom RBAC role that has an expiration date set to the next maintenance window.
Azure AD Privileged Identity Management allows administrators to assign vendors as eligible for the required Azure RBAC role instead of granting permanent membership. When needed, vendors submit an activation request that:
Is subject to the configured maximum duration (up to 24 hours, so eight hours is supported).
Triggers an approval workflow that can list the subscription owner as approver.
Is fully logged by PIM, recording the request, approval, and activation without custom code.
Access packages grant ongoing rather than just-in-time access, Azure Policy cannot by itself enforce per-activation approval, and simply creating a custom role with an expiration date lacks built-in approval and audit capabilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Azure AD Privileged Identity Management (PIM)?
Open an interactive chat with Bash
How does Azure AD PIM ensure just-in-time access for external vendors?
Open an interactive chat with Bash
What makes Azure AD PIM different from access packages in entitlement management?
Open an interactive chat with Bash
Microsoft Azure Solutions Architect Expert AZ-305
Design identity, governance, and monitoring solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .