Protego field desk
Security Operations, Identity and Compliance / 25-30% of exam

L8.Privileged Access & the Enterprise Access Model

Course outlineLesson 8 of 18

Remove standing privilege and isolate administrative paths with PIM, access reviews, cloud entitlement management, secure workstations, and the enterprise access model.

Map control-plane privilege

The enterprise access model focuses on control planes, management planes, and data or workload planes. Identify roles that can change identity, policy, networking, security tooling, code, or data. A narrow-looking role may still create a path to broader control.

Replace standing access

Use Microsoft Entra Privileged Identity Management for eligible, time-bound role activation with approval, justification, authentication, and alerting. Access reviews and entitlement management address ongoing need and lifecycle. Emergency accounts remain separate, monitored, and tested.

Include every cloud

Cloud infrastructure entitlement management evaluates effective permissions across multicloud resources. It helps identify unused, excessive, and risky entitlements that native role names alone may hide. Remediation still needs application-owner context and safe testing.

Protect the admin session

Secure administrative workstations, hardened browsers, dedicated admin identities, restricted remote access, and network boundaries reduce credential theft and session hijacking. Administration of SaaS tenants and infrastructure platforms belongs in the same privileged-access design. Decision rule: The more authority a role has over other identities or security controls, the stronger its activation, device, session, monitoring, and recovery requirements should be.

Exam Focus Points
  • Map privilege by effective control over identity, management, and workload planes
  • PIM provides eligible and time-bound access, while reviews validate continuing need
  • CIEM reveals effective and unused permissions across cloud platforms
  • Secure workstations protect the privileged session, not only the credential
Knowledge Check

1. Which design best reduces risk from a human administrator who needs occasional tenant-wide access?