A part of Microsoft Entra Privileged Identity Management that lets people become members or owners of a security group or Microsoft 365 group only when needed and only for a limited time. Activation can be made to require approval, a justification or MFA, as with role activation.
Also called formerly Privileged Access Groups, Privileged Access Groups.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains PIM for Groups in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra
The umbrella brand covering Microsoft's identity and network access portfolio. Internet Access, Private Access, External ID and ID Governance all belong to it, built on top of the core directory service, Entra ID.
- Privileged Identity Management
Capability in Microsoft Entra ID P2 that activates privileged roles just in time and for limited periods, with approval, justification and an audit trail.
- Security group
Kind of Entra group used to grant resource access. Its members, added by assignment or by dynamic rules, may be users, devices or service principals.
- Microsoft 365
Formerly Office 365, Microsoft's software-as-a-service productivity suite. A Microsoft Entra tenant provides its identity, and its data is not governed by Azure RBAC.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.