Memory hook: Identity is a boundary; privilege has an expiry.
Must remember
- Design workforce, external and workload identities separately. Entra ID, hybrid AD DS and B2B access have different lifecycle, authentication and trust requirements; decentralized identity addresses particular verification scenarios rather than replacing every account.
- Conditional Access combines user/workload context, device, risk and application requirements. Continuous access evaluation can improve supported revocation behavior; test emergency access and avoid blanket assumptions about token lifetime.
- Agent identities, including supported Entra Agent ID capabilities, need ownership, scope and policy. An agent should not inherit an unrestricted human administrator credential for every user request.
- Privileged Identity Management enables eligible/time-bound role activation with supported controls. Entitlement management and access reviews govern access packages and continued need; they are not substitutes for runtime authorization.
- Use the enterprise access model to protect administration across cloud tenants and on-premises systems. Secure privileged workstations, reduce standing privilege, harden AD DS and audit delegation.
- Manage secrets, keys and certificates with controlled lifecycle and recovery. Evaluate excessive cloud entitlements, external collaboration and dormant identities continuously, with accountable resource owners.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Administrators need occasional production elevation | Eligible scoped roles through PIM with appropriate approval and audit. |
| An agent acts for many users | A dedicated constrained identity plus supported user-context authorization where required. |
Traps
- MFA does not make every endpoint or session trustworthy.
- An access review identifies continued need; it does not replace a resource’s permission checks.
Active recall
1. How does authentication differ from authorization?
Authentication establishes identity; authorization determines allowed actions.
2. Why protect administrative workstations?
Compromised endpoints can steal or misuse highly privileged sessions.
3. What is standing privilege?
Privileged access continuously assigned even when no privileged task is being performed.
4. Why review B2B access?
External users’ business need and employment status can change outside your organization.
5. What should agent ownership include?
Responsible owner, allowed resources/actions, lifecycle, audit and incident response.