Which Entra tool evaluates and remediates privileged account risk?
You have three Azure subscriptions that are linked to a single Microsoft Entra tenant. You need to evaluate and remediate the risks associated with highly privileged accounts. The solution must minimize administrative effort. What should you use?
Community Votes
62% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you map the verbs "evaluate" and "remediate" permission risk to Permissions Management's Discover/Remediate capabilities, rather than reflexively choosing PIM because the scenario mentions highly privileged accounts.
Evaluating and remediating risk for highly privileged accounts across three Azure subscriptions in one Entra tenant is a cloud infrastructure entitlement management (CIEM) task handled by Microsoft Entra Permissions Management. This page establishes why Permissions Management (C) is the answer and where Privileged Identity Management (PIM) actually fits.
The most common wrong pick is PIM (B): candidates see "highly privileged accounts" and "Azure subscriptions" and assume just-in-time role activation is required, but PIM controls when roles are activated — it does not assess or right-size excessive permissions across subscriptions.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Microsoft Entra Permissions Management is a cloud infrastructure entitlement management (CIEM) service whose two headline capabilities are exactly the verbs used in this question: Discover, which lets you "assess permission risks by evaluating the gap between permissions granted and permissions used", and Remediate, which lets you right-size permissions and automate just-in-time access for cloud resources. Onboarding the Microsoft Entra tenant surfaces every Azure subscription attached to it — all three in this scenario — in a single dashboard, which is what satisfies the "minimize administrative effort" requirement. Permissions Management specifically flags highly privileged/super identities and their permission creep, so it both evaluates and remediates the risk the question describes. PIM, by contrast, is an access-activation control plane and produces no cross-subscription permission risk assessment.Why the Other Options Are Wrong
Global Secure Access (A) is Microsoft's Security Service Edge (SSE) stack for identity-centric network access such as ZTNA and internet/SaaS filtering, and has nothing to do with privileged role risk. Privileged Identity Management (B) is the closest distractor because it manages, controls and monitors access to privileged roles using eligibility, approval, MFA, justification and time-bound activation, but it never evaluates whether those role assignments are excessive; configuring PIM role settings per subscription also adds administrative effort rather than reducing it. Microsoft Entra Verified ID (D) issues and verifies decentralized verifiable credentials and is unrelated to privileged account risk. Only Permissions Management combines discovery of over-privileged identities with remediation actions in one tenant-wide view.Community Comment Notes
The top-voted comment from Steingalen argues for PIM, concluding you "should use Privileged Identity Management (PIM) (Option B)", but that reasoning shows only that PIM controls access, not that it evaluates permission risk. Ody voiced the tension directly: "Could make a case for PIM, but I think Microsoft wants to hear Permission Management." Nail quoted the product documentation verbatim — "Discover Customers can assess permission risks by evaluating the gap" — and linked the Permissions Management overview, while YesPlease simply posted "Answer C" with the same reference. Sc300ExamDemo hedged that "Only if the question asks about multi cloud, then I would go for C", and aocferreira rebutted that "it doesn't matter if its multi-cloud or not", since Permissions Management can be onboarded with Azure subscriptions alone. That Azure-only clarification removes the main objection to option C in this scenario.Official Reference
Exam Strategy
When an SC-300 scenario contains the verbs "evaluate" and "remediate" alongside permission or entitlement risk, map them to Permissions Management's Discover and Remediate capability, not to PIM. Reserve PIM for questions that describe time-bound, approval-based, just-in-time role activation or access reviews.
Frequently Asked Questions
Why is Privileged Identity Management (PIM) not the best answer for three Azure subscriptions?
PIM activates privileged roles just in time but gives no cross-subscription permission risk assessment. Permissions Management discovers and remediates over-provisioned privileged accounts in one tenant-wide view.
Does Microsoft Entra Permissions Management need AWS or GCP onboarding to work with Azure?
No. It can be onboarded with Azure subscriptions only, so it still centralizes permission risk evaluation for a single Entra tenant and its three subscriptions.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →