GregLab | Exam Prep

Design security operations, identity, and compliance capabilities

Privileged Access Architecture

Core

Protect enterprise control planes with explicit privilege tiers, just-in-time governance, multicloud entitlement visibility, recurring access validation, and hardened administrative devices.

Aligned to SC-100 skills measured as of October 21, 2026; candidates testing earlier should review the transition note in the lane overview.

Why this matters

Privileged access connects otherwise isolated systems. One overpowered identity or unmanaged workstation can collapse every boundary, so the architecture must reduce standing privilege, contain administrative paths, and prove that access remains necessary.

Must Know

  • The enterprise access model separates control plane, management plane, and data or workload plane so lower-trust administration cannot reach higher-impact systems.
  • PIM provides time-bound eligible activation and approval for privileged roles; entitlement management governs packaged access; access reviews validate continuing need.
  • Cloud-tenant administration needs dedicated identities, strong authentication, emergency access, least privilege, protected devices, logging, and provider-specific controls across every tenant.
  • Cloud infrastructure entitlement management analyzes permissions and effective access across clouds to expose excessive, unused, and risky privilege paths.
  • An access-review design defines accountable approvers, decision context, frequency, automatic outcomes, exception handling, and remediation verification.
  • Privileged access workstations isolate administration from productivity activity, enforce device health, and constrain where high-impact sessions can originate.
  • AD DS privileged governance must account for replication, delegated ACLs, service accounts, trusts, legacy protocols, and recovery of the directory control plane.

Compare and Distinguish

  • PIM changes how privileged roles are activated; access reviews reassess whether assignments remain justified; entitlement management automates governed request and lifecycle workflows.
  • CIEM reveals effective cloud permissions and toxic combinations, while a secure workstation protects the endpoint from which an administrator uses authorized privilege.

Scenario examples

  • Scenario: Engineers need subscription Owner only during approved incidents. Think: use eligible PIM assignments with short activation, strong authentication, approval, justification, and monitored emergency access.
  • Scenario: A multicloud team cannot explain inherited effective permissions. Think: add CIEM discovery and remediation while keeping provider-native enforcement and accountable role owners.

Exam traps

  • A quarterly access review does not eliminate the exposure from permanent Global Administrator assignments between reviews.
  • Remote access through a VPN does not make a general-purpose personal device safe for tier-zero administration.

Key takeaways

  • A management-plane role must not inherit control-plane reach through convenience groups.
  • PIM controls activation; entitlement management and access reviews govern different lifecycle stages.
  • A privileged session is only as trustworthy as its identity, device, and remote path.
How it works
  • Eligible assignments remain inactive until policy conditions are met, after which the time-bound role produces auditable privileged activity.
  • Hardened workstations restrict software, identity use, network paths, and device posture for administrative sessions.
Objects and administrative surfaces
  • Directory and resource roles, eligible assignments, activation policies, access packages, catalogs, review schedules, emergency accounts, and administrative units.
  • Privileged workstations, remote administration paths, cloud permission graphs, AD DS privileged groups, delegated ACLs, and tenant audit trails.
When to use it
  • Use tiered privileged-access architecture for any identity capable of changing trust, policy, security tooling, or recovery systems.
Security and governance implications
  • Set maximum privilege duration, approval authority, emergency-account custody, review outcomes, and exception expiration at enterprise level.
Troubleshooting signals
  • If PIM activations become routine all-day access, revisit role scope, task decomposition, duration, and approval evidence.
  • If reviews rubber-stamp access, provide usage, risk, owner, and business-justification context and enforce nonresponse outcomes.
More detail
  • Apply the enterprise access model to cloud and on-premises control planes.
  • Design PIM, packages, and reviews for distinct governance outcomes.
  • Specify secure administrative devices and multicloud entitlement analysis.

Ready for the quiz?

  • Which access lifecycle problem belongs to PIM rather than entitlement management?
  • How does CIEM complement provider-native roles?
  • Why should privileged remote access terminate on a controlled workstation?

Related objectives

  • D2.3.S1 — Design a solution for assigning and delegating privileged roles by using the enterprise access model
  • D2.3.S2 — Evaluate the security and governance of Microsoft Entra ID, including Microsoft Entra Privileged Identity Management (PIM), entitlement management, and access reviews
  • D2.3.S3 — Evaluate the security and governance of Active Directory Domain Services (AD DS), including resilience to common attacks
  • D2.3.S4 — Design a solution for securing the administration of cloud tenants, including SaaS and multicloud infrastructure and platforms
  • D2.3.S5 — Design a solution for cloud infrastructure entitlement management
  • D2.3.S6 — Evaluate an access review management solution
  • D2.3.S7 — Design a solution for secure workstations for privileged access, including remote access

Learn more

Free Microsoft Certified: Cybersecurity Architect Expert prep

Build focused SC-100 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-100 at a glance

Level
Expert
Duration
No SC-100-specific assessment duration published on the reviewed official pages
Questions
No fixed live question count published
Formats
No guaranteed question-type mix; the proctored exam may include interactive components
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-100. This lane contains multiple-choice and multiple-response exam-style practice aligned to the October 21, 2026 blueprint. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Expert-level cybersecurity architecture complexity rather than a Microsoft-published question rating.

Reference

SC-100 topics and reference map

Study links

SC-100 resources