An organization uses Microsoft Entra Permissions Management (CIEM - Cloud Infrastructure Entitlement Management) to monitor Azure AI service permissions. The security team wants to identify service principals with unused permissions to Azure OpenAI resources that have not been exercised in the past 90 days. Which Permissions Management capability provides this analysis?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because Microsoft Entra Permissions Management (formerly CloudKnox) provides a Permission Creep Index (PCI) that measures the gap between permissions granted and permissions actually used. By filtering for Cognitive Services or Azure OpenAI resource types, administrators can identify service principals, users, or groups that have been granted permissions to Azure OpenAI but have not used them in the past 90 days (or a configured period), enabling right-sizing through permission revocation.
Full explanation below image
Full Explanation
A is correct because Microsoft Entra Permissions Management (formerly CloudKnox) provides a Permission Creep Index (PCI) that measures the gap between permissions granted and permissions actually used. By filtering for Cognitive Services or Azure OpenAI resource types, administrators can identify service principals, users, or groups that have been granted permissions to Azure OpenAI but have not used them in the past 90 days (or a configured period), enabling right-sizing through permission revocation. B is wrong because the Entra admin center usage analytics shows sign-in patterns and app usage, not unused cloud resource permissions. C is wrong because Defender for Cloud CSPM recommends removing unused identities and excess permissions through security recommendations, but this is a posture tool—Permissions Management provides deeper CIEM analytics with usage data. D is wrong because Azure Advisor provides general best practice recommendations including right-sizing compute and cost optimization; it does not provide detailed identity permission usage analytics.