Which Entra tool evaluates and remediates privileged account risk?

Answer Correct answer: C — Microsoft Entra Permissions Management discovers and remediates privileged-account permission risk across the three Azure subscriptions from one console.

You have three Azure subscriptions that are linked to a single Microsoft Entra tenant. You need to evaluate and remediate the risks associated with highly privileged accounts. The solution must minimize administrative effort. What should you use?

  1. Global Secure Access
  2. Privileged Identity Management (PIM)
  3. Microsoft Entra Permissions Management Correct Answer
  4. Microsoft Entra Verified ID

Community Votes

B
62%
C
38%

62% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you map the verbs "evaluate" and "remediate" permission risk to Permissions Management's Discover/Remediate capabilities, rather than reflexively choosing PIM because the scenario mentions highly privileged accounts.

Evaluating and remediating risk for highly privileged accounts across three Azure subscriptions in one Entra tenant is a cloud infrastructure entitlement management (CIEM) task handled by Microsoft Entra Permissions Management. This page establishes why Permissions Management (C) is the answer and where Privileged Identity Management (PIM) actually fits.

The most common wrong pick is PIM (B): candidates see "highly privileged accounts" and "Azure subscriptions" and assume just-in-time role activation is required, but PIM controls when roles are activated — it does not assess or right-size excessive permissions across subscriptions.

Community Discussion (9 comments)

Steingalen 👍 10 Selected: B
To evaluate and remediate the risks associated with highly privileged accounts across multiple Azure subscriptions linked to a single Microsoft Entra tenant, you should use Privileged Identity Management (PIM) (Option B). Microsoft Entra PIM provides time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions on resources that you care about. It helps you manage, control, and monitor access within your organization, which includes access to Azure resources and other Microsoft services. Please note that while Microsoft Entra Permissions Management can provide visibility into permissions across multicloud infrastructures, it doesn’t specifically target the management of highly privileged accounts. Global Secure Access and Microsoft Entra Verified ID do not provide the specific capabilities required for this scenario.
Sneekygeek 👍 5 Selected: C
Answer is C
YesPlease 👍 1 Selected: C
Answer C) Microsoft Entra Permissions Management https://learn.microsoft.com/en-us/entra/permissions-management/
Frank9020 👍 2 Selected: C
To evaluate and remediate the risks associated with highly privileged accounts while minimizing administrative effort, you should use Microsoft Entra Permissions Management. This tool provides a comprehensive solution for managing permissions and roles across multiple cloud environments, including Azure
Nail 👍 1 Selected: C
I think it's got to be C. in the description: "Discover Customers can assess permission risks by evaluating the gap between permissions granted and permissions used." " Remediate Customers can right-size permissions based on usage, grant new permissions on-demand, and automate just-in-time access for cloud resources." https://learn.microsoft.com/en-us/entra/permissions-management/overview. I don't see how PIM does anything to "evaluate" risk.
aocferreira 👍 1 Selected: C
it doesn't matter if its multi-cloud or not, Entra Permissions Management can be used for Azure only without onboarding AWS or GCP. The answer is C as it provides this centralized location where we can easily check and fix the issues with permissions that have higher privileges..
Sc300ExamDemo 👍 2 Selected: B
Only if the question asks about multi cloud, then I would go for C "Entra Permission Management". Else just within Azure, PIM would suffice.
medi1520 👍 4 Selected: B
La respuesta es la B
Ody 👍 3
Could make a case for PIM, but I think Microsoft wants to hear Permission Management. The only thing that may not make it Permission Management is that it doesn't say multi-cloud.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Microsoft Entra Permissions Management is a cloud infrastructure entitlement management (CIEM) service whose two headline capabilities are exactly the verbs used in this question: Discover, which lets you "assess permission risks by evaluating the gap between permissions granted and permissions used", and Remediate, which lets you right-size permissions and automate just-in-time access for cloud resources. Onboarding the Microsoft Entra tenant surfaces every Azure subscription attached to it — all three in this scenario — in a single dashboard, which is what satisfies the "minimize administrative effort" requirement. Permissions Management specifically flags highly privileged/super identities and their permission creep, so it both evaluates and remediates the risk the question describes. PIM, by contrast, is an access-activation control plane and produces no cross-subscription permission risk assessment.

Why the Other Options Are Wrong

Global Secure Access (A) is Microsoft's Security Service Edge (SSE) stack for identity-centric network access such as ZTNA and internet/SaaS filtering, and has nothing to do with privileged role risk. Privileged Identity Management (B) is the closest distractor because it manages, controls and monitors access to privileged roles using eligibility, approval, MFA, justification and time-bound activation, but it never evaluates whether those role assignments are excessive; configuring PIM role settings per subscription also adds administrative effort rather than reducing it. Microsoft Entra Verified ID (D) issues and verifies decentralized verifiable credentials and is unrelated to privileged account risk. Only Permissions Management combines discovery of over-privileged identities with remediation actions in one tenant-wide view.

Community Comment Notes

The top-voted comment from Steingalen argues for PIM, concluding you "should use Privileged Identity Management (PIM) (Option B)", but that reasoning shows only that PIM controls access, not that it evaluates permission risk. Ody voiced the tension directly: "Could make a case for PIM, but I think Microsoft wants to hear Permission Management." Nail quoted the product documentation verbatim — "Discover Customers can assess permission risks by evaluating the gap" — and linked the Permissions Management overview, while YesPlease simply posted "Answer C" with the same reference. Sc300ExamDemo hedged that "Only if the question asks about multi cloud, then I would go for C", and aocferreira rebutted that "it doesn't matter if its multi-cloud or not", since Permissions Management can be onboarded with Azure subscriptions alone. That Azure-only clarification removes the main objection to option C in this scenario.

Official Reference

Exam Strategy

When an SC-300 scenario contains the verbs "evaluate" and "remediate" alongside permission or entitlement risk, map them to Permissions Management's Discover and Remediate capability, not to PIM. Reserve PIM for questions that describe time-bound, approval-based, just-in-time role activation or access reviews.

Frequently Asked Questions

Why is Privileged Identity Management (PIM) not the best answer for three Azure subscriptions?

PIM activates privileged roles just in time but gives no cross-subscription permission risk assessment. Permissions Management discovers and remediates over-provisioned privileged accounts in one tenant-wide view.

Does Microsoft Entra Permissions Management need AWS or GCP onboarding to work with Azure?

No. It can be onboarded with Azure subscriptions only, so it still centralizes permission risk evaluation for a single Entra tenant and its three subscriptions.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide