
Explanation:
Box 1: Privileged Identity Management (PIM) in Microsoft Entra ID
Privileged Identity Management provides time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions on resources that you care about. Here are some of the key features of Privileged Identity Management:
Provide just-in-time privileged access to Microsoft Entra ID and Azure resources Assign time- bound access to resources using start and end dates Require approval to activate privileged roles Enforce multifactor authentication to activate any role Use justification to understand why users activate Get notifications when privileged roles are activated Conduct access reviews to ensure users still need roles Download audit history for internal or external audit Prevents removal of the last active Global Administrator and Privileged Role Administrator role assignments Box 2: Microsoft Entra Permissions Management Microsoft Entra Permissions Management is a cloud infrastructure entitlement management (CIEM) solution that provides comprehensive visibility into permissions assigned to all identities (users and workloads), actions, and resources across cloud infrastructures. It detects, right-sizes, and monitors unused and excessive permissions and enables Zero Trust security through least privilege access in Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
Reference:
https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim- configure
https://learn.microsoft.com/en-us/entra/permissions-management/