nerdexam
Microsoft

MS-900 · Question #350

A company uses Microsoft 365. The company requires that you implement least privileged access. You need to recommend solutions that meet the requirements. Which two solutions should you recommend? Eac

The correct answer is C. Just-in-time (JIT) access D. Privileged Access Workstations (PAW) devices. Implementing least privileged access in Microsoft 365 requires solutions that minimize standing privileges and restrict access to sensitive administrative tasks. JIT access and PAW devices are both designed specifically to enforce least privilege principles.

Submitted by femi9· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

A company uses Microsoft 365. The company requires that you implement least privileged access. You need to recommend solutions that meet the requirements. Which two solutions should you recommend? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Exhibit

MS-900 question #350 exhibit

Options

  • ADevice compliance
  • BIP address range restrictions
  • CJust-in-time (JIT) access
  • DPrivileged Access Workstations (PAW) devices

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    22% (4)
  • C
    72% (13)

Why each option

Implementing least privileged access in Microsoft 365 requires solutions that minimize standing privileges and restrict access to sensitive administrative tasks. JIT access and PAW devices are both designed specifically to enforce least privilege principles.

ADevice compliance

Device compliance policies enforce security baselines on endpoints but do not control or limit the scope of user privileges, so they do not directly implement least privileged access.

BIP address range restrictions

IP address range restrictions are a conditional access control that limits where users can connect from, but they do not restrict the level of permissions or privileges a user holds, making them unrelated to least privilege.

CJust-in-time (JIT) accessCorrect

Just-in-time (JIT) access, available through Microsoft Entra Privileged Identity Management (PIM), ensures users only have elevated privileges for a limited time window when needed, eliminating standing administrative access and directly enforcing least privilege by granting rights only on demand and revoking them automatically after the session or approval period ends.

DPrivileged Access Workstations (PAW) devicesCorrect

Privileged Access Workstations (PAW) are hardened, dedicated devices used exclusively for administrative tasks, ensuring that privileged operations are performed from a secured, controlled environment that reduces the attack surface and enforces least privilege by isolating administrative actions from regular user activity.

Concept tested: Implementing least privileged access with JIT and PAW

Source: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure

Topics

#least privileged access#just-in-time access#Privileged Access Workstations#Zero Trust

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice