To manage Azure resource roles, PIM works through this service principal, which therefore requires User Access Administrator at subscription or management group level.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains MS-PIM in context, with comparison tables and the common traps.
Terms in this definition
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - Privileged Identity Management
Capability in Microsoft Entra ID P2 that activates privileged roles just in time and for limited periods, with approval, justification and an audit trail.
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- User Access Administrator
Granted Microsoft.Authorization/* actions, this Azure role handles role assignments and management locks, yet it can't write tags or manage any other resources. For creating or removing locks, no less-privileged role suffices.
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
- Management group
An Azure scope that sits over subscriptions. Policies and role assignments set there flow down to every subscription, resource group and resource it contains.