Your organization operates workloads across Azure, AWS, and GCP. You must discover all human and workload identities, inventory their effective permissions, identify unused permissions across clouds, and automatically right-size roles to least privilege with approval workflows. What should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Microsoft Entra Permissions Management for cross-cloud permissions discovery, risk analysis, and automated remediation (right-sizing).
Why this is the answer
Microsoft Entra Permissions Management (formerly CloudKnox) is a Cloud Infrastructure Entitlement Management (CIEM) solution designed specifically for multi-cloud environments (Azure, AWS, GCP). It provides comprehensive visibility into permissions, identifies high-risk permissions, detects unused or excessive permissions, and enables automated right-sizing of roles to enforce least privilege, often with approval workflows. Azure AD Privileged Identity Management (PIM) focuses on just-in-time access within Azure AD and connected Azure resources, not cross-cloud identity discovery or automated right-sizing of roles in AWS/GCP. Microsoft Defender for Cloud offers cloud security posture management and threat protection, but its primary function isn't detailed cross-cloud permissions inventory and automated right-sizing. Azure Lighthouse is for delegated management of Azure resources across tenants, not cross-cloud identity and access management. Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) focused on SaaS app security, not CIEM for IaaS/PaaS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed