Agent Foskett Academy • Microsoft Entra • Module 1 • Lesson 6

Lesson 6 — Privileged Identity Management Basics

Privileged roles provide powerful access to Microsoft Entra, Microsoft 365 and connected cloud services.

Microsoft Entra Privileged Identity Management helps organisations reduce permanent administrative access by making users eligible for roles and requiring controlled, time-limited activation when elevated permissions are needed.

This lesson explains eligible and active assignments, just-in-time activation, approval workflows, MFA, access reviews, alerts and the investigation process used to review privileged activity.

Privileged access should be temporary, justified, strongly authenticated and fully auditable.
Agent Foskett Microsoft Entra Privileged Identity Management lesson
What you will learn

This lesson explains how Microsoft Entra PIM reduces standing privilege and controls administrative role activation.

Eligible and active assignments
Just-in-time role activation
Approvals, MFA and duration
Access reviews and investigation

Learning objectives

After completing this lesson, you should be able to explain how Microsoft Entra PIM controls privileged role access.

  • Explain the purpose of Privileged Identity Management.
  • Compare eligible and active role assignments.
  • Describe just-in-time role activation.
  • Understand approvals, MFA, justification and activation duration.
  • Review PIM alerts, access reviews and audit history.

The problem this solves

Permanent administrator access increases the time during which a compromised account can be used to make high-impact changes.

PIM reduces this exposure by keeping privileged roles inactive until they are genuinely required.

What is Privileged Identity Management?

Microsoft Entra Privileged Identity Management provides time-based and approval-based activation for privileged roles.

It supports governance of Microsoft Entra roles, selected Azure resource roles and privileged access groups.

Traditional privileged access │ └── User permanently assigned Global Administrator │ └── Privilege available every hour of every day PIM-controlled privileged access │ ├── User is eligible for Global Administrator ├── User requests activation when required ├── MFA, justification and approval are evaluated ├── Role becomes active for a limited duration └── Privilege is removed automatically when activation expires
Agent Foskett tip:

The safest privileged role is one that is not active until the administrator genuinely needs it.

Standing privilege

Standing privilege means administrative permissions are continuously available to the assigned account.

This creates a larger attack window because stolen credentials or tokens can immediately access privileged functions.

Just-in-time administration

Just-in-time administration grants elevated access only for the period required to complete an approved task.

After the activation ends, the user returns to their normal level of access automatically.

Eligible compared with active assignments

AssignmentWhat it meansSecurity effect
EligibleThe user can request activation but does not currently hold the role permissions.Reduces standing privilege and limits the default attack surface.
ActiveThe role permissions are available immediately without activation.Creates continuous privileged access and greater exposure.
Time-bound eligibleThe user may activate the role only during a defined assignment period.Limits both eligibility and future role exposure.
Time-bound activeThe user holds active permissions until a specified expiry date.Better than permanent active access but still creates standing privilege during the assignment.

Role activation

An eligible user activates a role through PIM when administrative access is required.

The activation can require MFA, justification, a ticket number, approval and compliance with Conditional Access.

Activation duration

The maximum activation duration should reflect how long administrators genuinely need the role.

Shorter activation periods reduce exposure and encourage deliberate use of elevated access.

Typical PIM activation workflow

1. Administrator opens Microsoft Entra PIM 2. Administrator selects an eligible role 3. A reason and ticket number are entered 4. MFA or Conditional Access requirements are completed 5. An approver reviews the request when approval is required 6. The role becomes active for the configured duration 7. Administrative work is completed 8. The role expires or is manually deactivated 9. Activation and related actions remain available for audit

Require MFA on activation

Requiring MFA helps confirm that the person activating the role possesses an additional authentication factor.

For sensitive roles, phishing-resistant authentication should be considered through Conditional Access authentication strengths.

Require justification

A justification records why the administrator needs the role.

The explanation should be meaningful enough for approvers and investigators to understand the intended task.

Require a ticket number

A ticket number links the activation to an approved change, incident or service request.

This improves accountability and helps investigators compare the activation with the authorised work.

Require approval

Approval introduces a second person into the activation process for highly sensitive roles.

Approvers should verify the request, duration, user and business reason rather than treating approval as a routine click.

Approval workflow

Eligible administrator requests activation │ ├── Role: Global Administrator ├── Duration: 2 hours ├── Reason: Emergency Conditional Access repair └── Ticket: INC-4821 │ ├── Approver validates the request ├── Approval is granted or denied ├── User completes required controls └── Activation is recorded in audit history

Permanent assignments

Some emergency or service scenarios may require carefully governed permanent assignments, but these should be exceptional.

Permanent privileged access should be reviewed regularly and protected with strong authentication, monitoring and operational controls.

Emergency access accounts

Emergency access accounts help recover the tenant when normal administrative access is unavailable.

They should be excluded only from controls that could cause lockout, monitored closely and tested through a documented process.

PIM role settings

SettingPurpose
Activation maximum durationLimits how long the role can remain active during each elevation.
Require MFARequires stronger authentication when the user activates the role.
Require justificationRecords the reason for privileged access.
Require ticket informationLinks activation to an incident, change or service request.
Require approvalRequires an authorised approver to validate the request.
Notification settingsNotifies administrators, approvers or security teams about assignments and activations.

Access reviews

Access reviews ask whether users still require their privileged role assignments.

Reviews can identify leavers, transferred staff, unused assignments and excessive administrative access.

Review frequency

High-impact roles should be reviewed regularly based on organisational risk and compliance requirements.

Common review cycles include monthly, quarterly or twice yearly, with more frequent reviews for the most sensitive roles.

Questions for a privileged access review

Does the user still work in the role that requires this access? Does the user still need this specific privileged role? Has the role been activated recently? Is a less privileged role available? Is the assignment eligible or permanently active? Does the user have strong authentication configured? Are there unresolved risk detections or suspicious sign-ins? Should the assignment be approved, modified or removed?

PIM alerts

PIM can highlight risky privileged access configurations and behaviour.

Alerts help identify excessive permanent assignments, roles activated too frequently and other conditions that weaken privileged access governance.

Examples of concerns

Investigators should look for too many Global Administrators, stale assignments, unused roles, long activation windows and roles without approval or MFA controls.

The severity of each issue depends on the role, user, environment and compensating controls.

Privileged activation investigation workflow

1. Identify the user, role and activation time 2. Review whether the assignment was eligible or active 3. Confirm the activation reason, ticket and duration 4. Verify MFA and approval results 5. Review the Entra sign-in used for activation 6. Inspect device, IP address, location and risk information 7. Review directory audit logs during the activation window 8. Identify role assignments, policy changes and authentication changes 9. Correlate activity with Defender XDR and workload logs 10. Contain the account if the activation or actions were unauthorised
Agent Foskett investigation principle:

The activation explains when privilege became available. The audit trail explains what the privileged user did with it.

Review the activation context

Check the user, role, activation start time, expiry, reason, ticket, approval and whether the activation matched expected working activity.

An unusual time does not prove compromise, but it should increase scrutiny.

Review actions during elevation

Focus on high-impact changes made while the role was active.

Examples include adding administrators, changing Conditional Access, modifying authentication methods, creating applications or granting privileged consent.

Example investigation

1. A user activates Global Administrator at 2:15 AM 2. The request states “maintenance” but contains no ticket number 3. Approval is granted within seconds 4. The sign-in originates from an unfamiliar hosting-provider IP 5. MFA is satisfied using an existing session claim 6. A new privileged account is created 7. A Conditional Access policy is changed to report-only 8. A new authentication method is added to the privileged account 9. The analyst revokes sessions and disables the affected accounts 10. The activation, approval and administrative changes are escalated for incident response

Deactivation

Administrators can manually deactivate a role when the work is complete rather than waiting for expiry.

Early deactivation further reduces the period during which privileged access is available.

Privileged access groups

PIM can govern membership or ownership of selected privileged access groups.

This allows group-based access to become eligible, time-limited and approval controlled rather than permanently assigned.

Common mistakes

MistakeWhy it creates riskBetter practice
Leaving too many administrators permanently activeCompromised accounts have immediate privileged access.Use eligible assignments wherever operationally possible.
Allowing long activation durationsPrivilege remains available after the task may have finished.Set durations appropriate to the expected work.
Using approval without meaningful reviewRequests are approved automatically without validating risk.Train approvers to check user, role, reason, duration and ticket.
Ignoring PIM alerts and access reviewsStale or excessive privileged access persists.Review findings and remove unnecessary assignments.
Reviewing activation but not administrative actionsThe most important evidence may be what changed after elevation.Correlate activation history with directory and workload audit logs.

Key takeaways

  • PIM reduces standing privilege by making users eligible rather than permanently active.
  • Just-in-time activation limits privileged access to a defined period.
  • MFA, justification, ticket information and approval strengthen the activation process.
  • Access reviews help remove stale or unnecessary privileged assignments.
  • PIM alerts highlight risky privileged access configurations and behaviour.
  • Investigations must review both the activation and the actions performed while the role was active.

Continue learning

Continue through Module 1 — Entra Foundations, or return to the Microsoft Entra Academy roadmap.
⬅ Previous lesson
Lesson 5 — Risky Users and Risky Sign-insReview user risk, sign-in risk, identity detections and risk-based Conditional Access.
🏠 Academy home
Microsoft Entra AcademyReview the Entra roadmap and continue through the identity security learning path.
📘 Next lesson
Lesson 7 — Microsoft Entra Roles and Administrative UnitsLearn how Entra roles assign administrative permissions and how administrative units delegate management scope.

Microsoft Entra Privileged Identity Management Basics

Microsoft Entra Privileged Identity Management supports eligible role assignments, just-in-time activation, approval workflows, MFA, access reviews and privileged access auditing.

Microsoft Entra Academy Lesson 6 — Privileged Identity Management Basics

This Agent Foskett Microsoft Entra Academy lesson explains standing privilege, role activation, PIM settings, access reviews, alerts and privileged activity investigations.