← AZ-500: Azure security, historical path
AZ-500 and Azure Security Engineer Associate retired August31,2026. Independent historical content without Microsoft affiliation, accreditation, or certification award. SC-500 has its own syllabus. Editorial review without independent specialist verification. No live Azure changes, access policies, or real containment actions were executed. Fictional cases do not represent internal BNP Paribas policies. Trademarks belong to their respective owners.
01 / 6 · 40 MIN

Identity and temporary privilege

Connect principal, operation, scope, and activation.

Concept and mechanism

Authenticating a person or application does not define every operation they may perform. Azure roles control Azure resources, while Microsoft Entra roles control directory functions. Choose the role family and scope appropriate to the task. In PIM, an eligible assignment requires activation before use, with conditions such as approval or MFA according to configuration. An approved change window does not remove those conditions. Report-only Conditional Access evaluates impact without enforcing that policy’s controls; a Failure result in that mode can coexist with a successful sign-in. Validation should also consider enforced policies and the population actually observed.

Guided application

For workloads, managed identity avoids directly managing credentials but still needs target authorization. A system-assigned identity follows its resource: deleting and recreating a VM with the same name does not preserve the previous principal. A user-assigned identity has an independent lifecycle and can serve several resources, requiring review before removal. For APIs, distinguish delegated access, involving client and user, from app-only access, suitable for a noninteractive service where supported. At handover, record principals, grants, owners, and activation procedures. Test the minimum operation using the actual consumer identity instead of always using an administrator account.

IN PRACTICE

A recreated VM receives403 despite the same name. With networking validated, compare its new principal with the principal still authorized at the target.

Common pitfalls

Eligibility treated as active access; report-only treated as blocking; same name treated as same identity.

Related topics: Network boundaries and private access · Compute and operational access · Data protection and use

Take this idea with you

Demonstrate authorization for the effective identity at the required scope and time.

Create account

Reference: PIM eligible and active Azure resource roles · AZ-500 objectives2026-01-22; retired2026-08-31