Continue your lesson
Trace the identity, credential, token, assignment, policy decision, resource, and audit record for each access request.
Block 1 of 3Compare PIM for Azure resources · PIM role settings
Current · 15 min
Compare PIM for Azure resources · PIM role settings
Optional concept notes
PIM role settings
Configure activation duration MFA justification notification and approval requirements.
PIM for Azure resources
Governs eligible and active Azure role assignments at the intended resource scope.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 2 of 3Compare PIM eligible role assignment · PIM active role assignment · PIM role activation · PIM activation approval
18 min
Compare PIM eligible role assignment · PIM active role assignment · PIM role activation · PIM activation approval
Optional concept notes
PIM eligible role assignment
Allows a user to activate a privileged role when needed instead of holding it continuously.
PIM active role assignment
Grants the privileged role without requiring a separate activation for the assignment period.
PIM role activation
Temporarily changes an eligible assignment into active privileged access after requirements are met.
PIM activation approval
Requires a designated approver before an eligible user receives active role access.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Block 3 of 3Compare Privileged access group · Emergency access account
15 min
Compare Privileged access group · Emergency access account
Optional concept notes
Emergency access account
Provides a monitored cloud-only administrative path for tenant lockout recovery.
Privileged access group
Uses PIM to govern time-bound membership or ownership of a designated group.
Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.
Your lesson stays open here while the provider opens in another tab. Choose one source; the notes above are optional.
Practice the reasoning here
Use a fictional tenant. Draw one access path, apply least privilege, test an exception, and name the logs that would confirm the result.
- State the expected result before changing or testing anything.
- Name the observation, command, log, or report that would confirm it.
- Explain why the closest alternative does not fit the same requirement.
Check the whole objective
This unlocks objective 4.3 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.