Capability in Microsoft Entra ID P2 that activates privileged roles just in time and for limited periods, with approval, justification and an audit trail.
Also called PIM, Azure AD PIM, PIM.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104SC-500SC-900AB-900SC-300MD-102ALZ
Each book explains Privileged Identity Management in context, with comparison tables and the common traps.
Terms in this definition
- Capability
Something that a person, organisation or system is able to do.
- Microsoft Entra ID P2
Premium licence tier for Microsoft Entra ID that brings ID Protection, which Conditional Access needs for risk-based rules.
- Audit
Policy effect that lets a request proceed but flags the resource as non-compliant and logs a warning to the activity log. Microsoft suggests beginning there and later moving to something enforcing, like Deny.
Related terms
- Access reviews
Microsoft Entra ID Governance capability that periodically asks reviewers or users themselves to confirm membership for guests, app users or groups, removing anyone who does not respond. PIM, by contrast, handles privileged roles.
- Active assignment
Type of PIM assignment that grants the role straight away, with no activation step, for as long as the assignment lasts.
- Authentication context
A Conditional Access tag placed on just one sensitive area or action within an app (a particular SharePoint site, say, or activating a PIM role), so tougher sign-in conditions apply there without covering everything else in the app.
- Eligible assignment
A role assignment in PIM that has no effect until the user activates it, satisfying whatever MFA, justification or approval is required.
- Entra ID P2
Entra licence tier that adds Privileged Identity Management, access reviews and Identity Protection.
- JIT
Approach where access is switched on only at the moment it is needed and expires after a set time; examples are PIM role activation and JIT VM access, which opens ports 3389 or 22 temporarily.
- MS-PIM
To manage Azure resource roles, PIM works through this service principal, which therefore requires User Access Administrator at subscription or management group level.
- PIM activation
How a user with an eligible PIM assignment gets the role active for a limited time. The person asking can never be the one who approves it.