FREE STUDY NOTES · SC-500

Privileged Identity Management: eligible vs active assignments and role settings

How PIM activation, approval, maximum duration and notifications work, and what each role setting controls.

From Ultra Transcenders SC-500 by Tony Rough (publishing soon)

PIM replaces standing administrator access with eligible assignments that users activate when needed. Every Microsoft Entra role has its own settings that decide how activation and assignment behave.

Microsoft Entra Privileged Identity Management (Azure AD PIM) role settings split into two groups: activation settings, which apply when an eligible user activates the role, and assignment settings, which apply to the assignment itself or to the admin making it.

Setting What it controls What it does not do
Activation maximum duration (hours) Length of each activation of an eligible assignment (e.g. 1 day, 5 h, 2 h); PIM then removes the role automatically Doesn’t limit direct active assignments or delay activation
Require approval to activate Request waits for a designated approver; off = no approver at all —
Require justification on activation User types a reason Nobody reviews it
Require MFA on activation MFA at activation, enforced regardless of the user’s per-user MFA status —
Expire eligible assignments after Lifetime of eligible assignments (e.g. 3 months) Not activation length
Expire active assignments after Maximum length of a direct active assignment (e.g. 15 days allows a 2-day active assignment) Not activation length
Allow permanent eligible/active assignment Can be disallowed so every assignment expires —
Require MFA / justification on active assignment Applies to the admin creating the active assignment Not to the assigned end user

Common trap: Editing the role’s assignment settings to cap how long an activation lasts - assignment settings govern the assignments themselves; the cap on each activation is Activation maximum duration on the Activation tab.

Approvers

Active versus eligible assignments

An eligible assignment moves through an activation request (MFA, justification, ticket), an optional approval that no one can give themselves, and an active role that lasts for the activation maximum duration before PIM removes it. If approval isn't required, the request goes straight to active. Below, an active assignment is already in effect at sign-in with no request or approval, and ends at the assignment end date.
Figure 1.1: Activating an eligible PIM assignment compared with an active assignment

Common trap: Assuming a time-bound active assignment still grants the role after its end date - a one-month active assignment starting on 1 May expires on 1 June, so the user has no role on 15 June; and because it was an active assignment, the user was never eligible and has nothing to activate either.

Get the whole book

This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · Free SC-500 glossary · All SC-500 study notes

More SC-500 study notes