Separate the admin plane
The privileged interface uses a distinct hostname, Conditional Access policy and access path. Eligible roles activate through PIM rather than remaining permanently assigned.
Reduces:Session theft, privilege persistence and accidental administration.