How PIM activation, approval, maximum duration and notifications work, and what each role setting controls.
From Ultra Transcenders SC-500 by Tony Rough (publishing soon)
PIM replaces standing administrator access with eligible assignments that users activate when needed. Every Microsoft Entra role has its own settings that decide how activation and assignment behave.
Microsoft Entra Privileged Identity Management (Azure AD PIM) role settings split into two groups: activation settings, which apply when an eligible user activates the role, and assignment settings, which apply to the assignment itself or to the admin making it.
| Setting | What it controls | What it does not do |
|---|---|---|
| Activation maximum duration (hours) | Length of each activation of an eligible assignment (e.g. 1 day, 5 h, 2 h); PIM then removes the role automatically | Doesn’t limit direct active assignments or delay activation |
| Require approval to activate | Request waits for a designated approver; off = no approver at all | — |
| Require justification on activation | User types a reason | Nobody reviews it |
| Require MFA on activation | MFA at activation, enforced regardless of the user’s per-user MFA status | — |
| Expire eligible assignments after | Lifetime of eligible assignments (e.g. 3 months) | Not activation length |
| Expire active assignments after | Maximum length of a direct active assignment (e.g. 15 days allows a 2-day active assignment) | Not activation length |
| Allow permanent eligible/active assignment | Can be disallowed so every assignment expires | — |
| Require MFA / justification on active assignment | Applies to the admin creating the active assignment | Not to the assigned end user |
Common trap: Editing the role’s assignment settings to cap how long an activation lasts - assignment settings govern the assignments themselves; the cap on each activation is Activation maximum duration on the Activation tab.
Common trap: Assuming a time-bound active assignment still grants the role after its end date - a one-month active assignment starting on 1 May expires on 1 June, so the user has no role on 15 June; and because it was an active assignment, the user was never eligible and has nothing to activate either.
This note is one section of Ultra Transcenders SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · Free SC-500 glossary · All SC-500 study notes
How a Conditional Access policy is built and how multiple policies combine.
Why control-plane roles can't read secrets, and which Key Vault role or access policy each task needs.
What Deny, Audit, Append, Modify and DeployIfNotExists do, and when you need a remediation task and managed identity.
Account keys, account and service SAS, user delegation SAS and Entra RBAC compared by scope and revocability.
Where each Azure SQL data protection feature works and who it protects data from.
How security admin rules are evaluated before NSGs, and when to use Allow, Deny or Always allow.
How JIT locks management ports and opens them on request, with the plan and permissions it needs.