Checklist
PIM implementation checklist
Based on the article: Privileged Identity Management: just-in-time Microsoft Entra roles done properly · 6 min read
Standing Global Administrators are the easiest win for an attacker and the hardest thing to explain to an auditor. Privileged Identity Management (PIM) turns permanent role assignments into eligible ones that admins activate for a few hours, with MFA, a justification and optionally an approval. In this post I'll walk through the concepts, the role settings that matter, the activation and approval flow, PIM for Groups, alerts and reviews, and the activation problems that generate most of the tickets.
Before you start
- Licensing: Microsoft Entra ID P2 or Microsoft Entra ID Governance (also part of Microsoft Entra Suite). You need a licence for every user with an eligible or time-bound assignment, every approver, and everyone reviewing or being reviewed in a role access review. If the licence lapses, eligible assignments are removed.
- Roles: Privileged Role Administrator (or Global Administrator) manages assignments and role settings; Security Administrator, Security Reader and Global Reader can view them.
- Emergency access: two cloud-only accounts permanently assigned Global Administrator, excluded from Conditional Access and never made eligible.
- Nothing to switch on: once the tenant is licensed PIM is available immediately; the
MS-PIMservice principal appearing in audit logs is expected.
How it works
| Term | Meaning |
|---|---|
| Eligible | The user must activate before using the role. Once active, the permissions equal a permanent assignment. |
| Active | Usable straight away. Both eligible and active assignments can be permanent or time-bound. |
| Activation | The steps the role settings demand (MFA or an authentication context, a reason, a ticket number, approval), producing a temporary active assignment capped by the maximum duration. |
| Extend / renew | User-requested before or after a time-bound assignment expires; a Privileged Role Administrator or Global Administrator approves. |
Checklist
- 1
Configure role settings
Settings are per role, and every assignment of that role follows them. Go to ID Governance › Privileged Identity Management › Microsoft Entra roles › Roles, select the role, then Role settings › Edit.
Setting What I recommend Activation maximum duration 1 to 24 hours. Four hours suits most roles; shorter for Global Administrator. On activation, require Either Microsoft Entra ID multifactor authentication or Microsoft Entra Conditional Access authentication context. Use the context for phishing-resistant MFA, a compliant device or terms of use at activation time. Require justification / ticket information Justification yes. The ticket field is free text; nothing validates it. Require approval to activate Yes for Global Administrator, Privileged Role Administrator and similar. Pick at least two approvers; with none selected, active Privileged Role Administrators and Global Administrators approve by default. Assignment duration Allow permanent eligible assignments or make eligibility expire; the same choice exists for active assignments, plus MFA and justification when an active assignment is created. Notifications Per email type, change recipients or keep critical emails only. Watch out: you lock yourself out if every Global Administrator and Privileged Role Administrator is only eligible, approval is required, and no approvers are configured. Keep the emergency access accounts permanently active and name specific approvers.
- Authentication context done right — Create and enable the Conditional Access policy that targets the authentication context before you reference it in the role settings. Scope it to all users or the eligible users, never to the directory role: during activation the user doesn't hold the role yet, so a role-scoped policy wouldn't apply.
- 2
Convert standing admins to eligible
Open Microsoft Entra roles › Discovery and insights (preview). Reduce Global Administrators and Eliminate standing access list the permanent assignments and let you select users and choose Make eligible or Remove assignment.
- 3
Activate, approve, deactivate
- The admin goes to ID Governance › Privileged Identity Management › My roles › Microsoft Entra roles and selects Activate next to the role.
- If prompted, they complete Additional verification required. This happens once per session.
- They can reduce the scope, set a custom start time, enter the reason and select Activate. If approval is required, a notification says the request is pending and it appears under My requests, where it can also be cancelled.
- Approvers get an email and act in Approve requests, entering a justification. The first approver to respond decides, approvers can't approve their own requests, and a request not approved within 24 hours expires. That window isn't configurable.
- Once active, a Deactivate button appears, but not within the first five minutes of activation.
Scripted activation uses the same Microsoft Graph API the portal does:
POST https://graph.microsoft.com/v1.0/roleManagement/directory/roleAssignmentScheduleRequests { "action": "selfActivate", "principalId": "<user object id>", "roleDefinitionId": "<role template id>", "directoryScopeId": "/", "justification": "Change CHG0012345: mailbox migration", "scheduleInfo": { "expiration": { "type": "AfterDuration", "duration": "PT4H" } } } - 4
PIM for Groups
PIM for Groups makes membership or ownership of a security or Microsoft 365 group eligible, with separate member and owner policies. Dynamic groups and on-premises synced groups can't be enabled.
Note: to give just-in-time access to Exchange, SharePoint or Purview roles, make the users active members and make the group eligible for the role, or use PIM for Entra roles directly. Making users eligible for a group that holds the role is documented to cause activation delays, and SharePoint and OneDrive can return "Access denied" for up to 24 hours.
- 5
Alerts and access reviews
Under Microsoft Entra roles › Alerts › Setting, tune the built-in alerts: Roles are being assigned outside of Privileged Identity Management (high), Potential stale accounts in a privileged role (medium), and low-severity ones such as There are too many Global Administrators and Roles are being activated too frequently.
Verify
- My roles › Active assignments shows the role with its end time, and the admin can perform the privileged task.
- Microsoft Entra roles › Resource audit lists the activation, the approver's decision and the deactivation.
- In the Entra sign-in logs, the activation sign-in shows the authentication context policy under the Conditional Access tab.
- The weekly PIM digest and alert emails arrive for the recipients you configured.
Tips & gotchas
- "It never asked me for MFA." Documented behaviour: a user who already satisfied MFA in the session, including through a Windows Hello for Business sign-in, isn't prompted again. Use the authentication context with sign-in frequency Every time for a fresh prompt.
- Activation blocked by Conditional Access. Check the policy targeting the authentication context: enabled (not report-only), user in scope, device compliant, authentication strength registered. The user sees a message that a Conditional Access policy may require additional verification and must select it to continue.
- Role active, access still denied. PIM creates the assignment within seconds, but applications cache role state. Signing out and back in usually helps; the SharePoint and OneDrive case above is the documented exception.
- Approval expired. After 24 hours the requester must submit a new request, so use a group as approver rather than one person.
- Teams on mobile asks the user to reopen the app after an activation to keep receiving notifications. By design.