Lesson 6 — Privileged Identity Management Basics
Privileged roles provide powerful access to Microsoft Entra, Microsoft 365 and connected cloud services.
Microsoft Entra Privileged Identity Management helps organisations reduce permanent administrative access by making users eligible for roles and requiring controlled, time-limited activation when elevated permissions are needed.
This lesson explains eligible and active assignments, just-in-time activation, approval workflows, MFA, access reviews, alerts and the investigation process used to review privileged activity.

What you will learn
This lesson explains how Microsoft Entra PIM reduces standing privilege and controls administrative role activation.
Learning objectives
After completing this lesson, you should be able to explain how Microsoft Entra PIM controls privileged role access.
- Explain the purpose of Privileged Identity Management.
- Compare eligible and active role assignments.
- Describe just-in-time role activation.
- Understand approvals, MFA, justification and activation duration.
- Review PIM alerts, access reviews and audit history.
The problem this solves
Permanent administrator access increases the time during which a compromised account can be used to make high-impact changes.
PIM reduces this exposure by keeping privileged roles inactive until they are genuinely required.
What is Privileged Identity Management?
Microsoft Entra Privileged Identity Management provides time-based and approval-based activation for privileged roles.
It supports governance of Microsoft Entra roles, selected Azure resource roles and privileged access groups.
The safest privileged role is one that is not active until the administrator genuinely needs it.
Standing privilege
Standing privilege means administrative permissions are continuously available to the assigned account.
This creates a larger attack window because stolen credentials or tokens can immediately access privileged functions.
Just-in-time administration
Just-in-time administration grants elevated access only for the period required to complete an approved task.
After the activation ends, the user returns to their normal level of access automatically.
Eligible compared with active assignments
| Assignment | What it means | Security effect |
|---|---|---|
| Eligible | The user can request activation but does not currently hold the role permissions. | Reduces standing privilege and limits the default attack surface. |
| Active | The role permissions are available immediately without activation. | Creates continuous privileged access and greater exposure. |
| Time-bound eligible | The user may activate the role only during a defined assignment period. | Limits both eligibility and future role exposure. |
| Time-bound active | The user holds active permissions until a specified expiry date. | Better than permanent active access but still creates standing privilege during the assignment. |
Role activation
An eligible user activates a role through PIM when administrative access is required.
The activation can require MFA, justification, a ticket number, approval and compliance with Conditional Access.
Activation duration
The maximum activation duration should reflect how long administrators genuinely need the role.
Shorter activation periods reduce exposure and encourage deliberate use of elevated access.
Typical PIM activation workflow
Require MFA on activation
Requiring MFA helps confirm that the person activating the role possesses an additional authentication factor.
For sensitive roles, phishing-resistant authentication should be considered through Conditional Access authentication strengths.
Require justification
A justification records why the administrator needs the role.
The explanation should be meaningful enough for approvers and investigators to understand the intended task.
Require a ticket number
A ticket number links the activation to an approved change, incident or service request.
This improves accountability and helps investigators compare the activation with the authorised work.
Require approval
Approval introduces a second person into the activation process for highly sensitive roles.
Approvers should verify the request, duration, user and business reason rather than treating approval as a routine click.
Approval workflow
Permanent assignments
Some emergency or service scenarios may require carefully governed permanent assignments, but these should be exceptional.
Permanent privileged access should be reviewed regularly and protected with strong authentication, monitoring and operational controls.
Emergency access accounts
Emergency access accounts help recover the tenant when normal administrative access is unavailable.
They should be excluded only from controls that could cause lockout, monitored closely and tested through a documented process.
PIM role settings
| Setting | Purpose |
|---|---|
| Activation maximum duration | Limits how long the role can remain active during each elevation. |
| Require MFA | Requires stronger authentication when the user activates the role. |
| Require justification | Records the reason for privileged access. |
| Require ticket information | Links activation to an incident, change or service request. |
| Require approval | Requires an authorised approver to validate the request. |
| Notification settings | Notifies administrators, approvers or security teams about assignments and activations. |
Access reviews
Access reviews ask whether users still require their privileged role assignments.
Reviews can identify leavers, transferred staff, unused assignments and excessive administrative access.
Review frequency
High-impact roles should be reviewed regularly based on organisational risk and compliance requirements.
Common review cycles include monthly, quarterly or twice yearly, with more frequent reviews for the most sensitive roles.
Questions for a privileged access review
PIM alerts
PIM can highlight risky privileged access configurations and behaviour.
Alerts help identify excessive permanent assignments, roles activated too frequently and other conditions that weaken privileged access governance.
Examples of concerns
Investigators should look for too many Global Administrators, stale assignments, unused roles, long activation windows and roles without approval or MFA controls.
The severity of each issue depends on the role, user, environment and compensating controls.
Privileged activation investigation workflow
The activation explains when privilege became available. The audit trail explains what the privileged user did with it.
Review the activation context
Check the user, role, activation start time, expiry, reason, ticket, approval and whether the activation matched expected working activity.
An unusual time does not prove compromise, but it should increase scrutiny.
Review actions during elevation
Focus on high-impact changes made while the role was active.
Examples include adding administrators, changing Conditional Access, modifying authentication methods, creating applications or granting privileged consent.
Example investigation
Deactivation
Administrators can manually deactivate a role when the work is complete rather than waiting for expiry.
Early deactivation further reduces the period during which privileged access is available.
Privileged access groups
PIM can govern membership or ownership of selected privileged access groups.
This allows group-based access to become eligible, time-limited and approval controlled rather than permanently assigned.
Common mistakes
| Mistake | Why it creates risk | Better practice |
|---|---|---|
| Leaving too many administrators permanently active | Compromised accounts have immediate privileged access. | Use eligible assignments wherever operationally possible. |
| Allowing long activation durations | Privilege remains available after the task may have finished. | Set durations appropriate to the expected work. |
| Using approval without meaningful review | Requests are approved automatically without validating risk. | Train approvers to check user, role, reason, duration and ticket. |
| Ignoring PIM alerts and access reviews | Stale or excessive privileged access persists. | Review findings and remove unnecessary assignments. |
| Reviewing activation but not administrative actions | The most important evidence may be what changed after elevation. | Correlate activation history with directory and workload audit logs. |
Key takeaways
- PIM reduces standing privilege by making users eligible rather than permanently active.
- Just-in-time activation limits privileged access to a defined period.
- MFA, justification, ticket information and approval strengthen the activation process.
- Access reviews help remove stale or unnecessary privileged assignments.
- PIM alerts highlight risky privileged access configurations and behaviour.
- Investigations must review both the activation and the actions performed while the role was active.
Related Agent Foskett resources
Continue learning
Microsoft Entra Privileged Identity Management Basics
Microsoft Entra Privileged Identity Management supports eligible role assignments, just-in-time activation, approval workflows, MFA, access reviews and privileged access auditing.
Microsoft Entra Academy Lesson 6 — Privileged Identity Management Basics
This Agent Foskett Microsoft Entra Academy lesson explains standing privilege, role activation, PIM settings, access reviews, alerts and privileged activity investigations.
