Microsoft Entra Privileged Identity Management (PIM) removes standing admin access by turning permanent role assignments into eligible ones: an administrator holds no privileges until they activate the role for a limited time, from one to 24 hours, after passing the checks you configure, such as MFA, a justification and an approval. To set it up, inventory who holds privileged roles today, configure the role settings for each role, assign administrators as eligible, remove their active assignments, and keep two emergency access accounts as permanent active Global Administrators. PIM needs Microsoft Entra ID P2 or Microsoft Entra ID Governance licenses for the people it governs.
Who this is for and what you will have
This guide is for identity and security administrators who want to reduce how many accounts hold Global Administrator, Exchange Administrator, Azure Owner and similar roles at any moment. It covers Microsoft Entra roles in detail and Azure resource roles more briefly. At the end you will have:
- An inventory of standing (active) privileged assignments and who holds them.
- Role settings that require MFA, a justification and, for the most sensitive roles, approval.
- Administrators converted from active to eligible assignments.
- A tested activation process and PIM alerts that tell you when roles are assigned outside PIM.
PIM works best on top of strong authentication. If you haven't required MFA for all users yet, start with the Microsoft 365 MFA rollout plan. Just-in-time admin access is also one of the building blocks of a zero trust access architecture.
Key concepts
| Term | Meaning |
|---|---|
| Eligible | The user must activate the role before using it. Activation can require MFA, a justification or approval. |
| Active | The user has the role's permissions without doing anything. |
| Permanent | The assignment has no end date. |
| Time-bound | The assignment has a start and end date. |
| Activate | The process an eligible user follows to use the role for a limited period. |
Eligible and active assignments grant exactly the same permissions once active. The difference is only whether the person has them all the time. PIM also prevents removal of the last active Global Administrator and Privileged Role Administrator assignments.
Licensing and permissions
You need Microsoft Entra ID P2 or Microsoft Entra ID Governance licenses for:
- Users with eligible or time-bound assignments to Microsoft Entra or Azure roles managed in PIM.
- Users with eligible or time-bound assignments as members or owners in PIM for Groups.
- Users who approve or reject activation requests.
- Users assigned to an access review, and users who perform access reviews.
Microsoft's own licensing example: if 14 administrators are managed through PIM and three other people can approve activations, you need 17 licenses. Count everyone in these categories before you start. Microsoft Entra ID P2 is included in Microsoft 365 E5.
To manage assignments for Microsoft Entra roles you need the Privileged Role Administrator role (or Global Administrator). For Azure resource roles you need Owner or User Access Administrator on the resource, or to be a subscription administrator.
Prerequisites
- Licensing in place as above.
- Two cloud-only emergency access accounts with phishing-resistant authentication (FIDO2 passkey or certificate-based authentication), excluded from Conditional Access policies that block sign-in.
- MFA registered by every administrator who will activate roles.
- Microsoft Graph PowerShell (
Microsoft.Graph.Identity.Governancemodule) for the inventory step. - An agreed list of approvers for the highest-privilege roles, with at least two per role.
Step 1: Inventory standing privileged access
In the Microsoft Entra admin center, browse to ID Governance > Privileged Identity Management > Microsoft Entra roles > Roles, open each privileged role and review the Active roles tab. Anything listed there that isn't an emergency access account is a candidate to convert.
For the whole tenant at once, list active assignment instances with Microsoft Graph PowerShell. AssignmentType is Assigned for standing assignments and Activated for roles someone activated through PIM:
Connect-MgGraph -Scopes 'RoleAssignmentSchedule.Read.Directory'
$standing = Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -All `
-Filter "assignmentType eq 'Assigned'" -ExpandProperty roleDefinition
$standing | Select-Object PrincipalId,
@{n='Role';e={$_.RoleDefinition.DisplayName}},
MemberType, StartDateTime, EndDateTime |
Sort-Object Role | Export-Csv .\standing-role-assignments.csv -NoTypeInformationMemberType shows whether the assignment is Direct, Group or Inherited, and EndDateTime shows whether and when it ends. Resolve each PrincipalId to a user, group or service principal and decide, per person, which role they actually need. Replacing Global Administrator with a narrower role such as Exchange Administrator or User Administrator is often a bigger win than PIM itself.
Step 2: Configure role settings
Role settings (also called PIM policies) are defined per role, and every assignment to that role follows them.
- Sign in to the Microsoft Entra admin center as at least a Privileged Role Administrator.
- Browse to ID Governance > Privileged Identity Management > Microsoft Entra roles > Roles.
- Select the role, then Role settings, then Edit.
- Configure the settings below and select Update.
| Setting | What it controls |
|---|---|
| Activation maximum duration | Maximum hours an activation lasts, from one to 24 |
| On activation, require | Microsoft Entra multifactor authentication, or a Conditional Access authentication context |
| Require justification on activation | User must enter a business reason |
| Require ticket information on activation | User must enter a ticket number (not validated against any system) |
| Require approval to activate | Selected approvers must approve each activation |
| Allow permanent eligible assignment / Expire eligible assignment after | Whether eligible assignments can be permanent |
| Allow permanent active assignment / Expire active assignment after | Whether active assignments can be permanent |
| Require multifactor authentication on active assignment | Admin must do MFA when creating an active assignment |
| Require justification on active assignment | Admin must give a reason when creating an active assignment |
| Notifications | Who receives emails for assignments, activations and approvals |
A practical starting point is to require MFA and a justification on every role, require approval for Global Administrator and Privileged Role Administrator, keep activation short for the most powerful roles, and expire eligible assignments so they are reviewed. Adjust to your operating model. PIM raises a Roles are being activated too frequently alert when a user activates the same role several times within a set period; Microsoft treats that as a possible sign of attack, so review those users and also check that the activation duration is long enough for their tasks.
Avoid an approval lockout
If every Global Administrator and Privileged Role Administrator assignment is eligible, approval is required, and no approvers are configured, nobody can approve activations and you're locked out. When no approvers are selected, active Privileged Role Administrators and Global Administrators are the default approvers. Always name specific approvers and keep your emergency access accounts permanently active.
Step 3: Require a Conditional Access authentication context (optional)
The On activation, require multifactor authentication setting may not prompt a user who already did MFA in the session. To force stronger checks at activation, for example a phishing-resistant method or a compliant device, use an authentication context:
- Create an authentication context in Conditional Access.
- Create a Conditional Access policy that targets that authentication context, includes all users or the eligible users, and requires an authentication strength. To force reauthentication on every activation, set sign-in frequency to Every time under Session controls.
- Enable that policy, then select the authentication context under On activation, require in the role settings.
Don't scope this policy to the directory role itself. During activation the user doesn't have the role yet, so a role-scoped policy wouldn't apply. If you also want requirements while the role is in use, create a second policy that targets the directory roles. After a user reauthenticates for one activation, a 10-minute window applies across Microsoft Entra roles, Azure resource roles and PIM for Groups.
Create and enable the Conditional Access policy before configuring the context in PIM. If no policy targets the context, PIM falls back to requiring MFA, but that fallback doesn't apply if the policy is off, in report-only mode or excludes the user.
Step 4: Assign eligible roles
- Browse to ID Governance > Privileged Identity Management > Microsoft Entra roles > Roles and select Add assignments.
- Select Select a role, choose the role and the member (user or group), and select Next.
- Set Assignment type to Eligible.
- Choose permanent or set start and end dates for a time-bound assignment, then select Assign.
Assignments can't be shorter than five minutes and can't be removed within five minutes of being created. For roles that support it, you can restrict the scope to an administrative unit from Entra ID > Roles & admins instead of granting the role tenant-wide.
You can also create eligible assignments with Microsoft Graph by posting to roleManagement/directory/roleEligibilityScheduleRequests with the action adminAssign.
Step 5: Remove the standing assignments
When each administrator has an eligible assignment and has tested activation, remove the active one:
- Open the role in Microsoft Entra roles > Roles.
- On the Active roles tab, find the assignment and select Remove.
You can't remove the last active Global Administrator assignment. That is why the emergency access accounts must stay permanently active: they become the active Global Administrators that let everyone else be eligible.
Step 6: Bring Azure resource roles into PIM
Azure Owner, Contributor and User Access Administrator assignments on subscriptions are just as sensitive as directory roles.
- Sign in as at least a User Access Administrator on the resource.
- Browse to ID Governance > Privileged Identity Management > Azure resources.
- Select a management group or subscription, then Select to open it.
- Under Manage, select Roles, then Add assignments.
- Choose the role and member, set Assignment type to Eligible on the Settings tab, set the duration and select Assign.
Azure resource roles have their own role settings, defined at the resource scope rather than tenant-wide. If you are designing subscription access for a larger migration, the enterprise Azure cloud migration playbook covers how landing zones and management groups shape where these assignments belong.
Step 7: Activate a role
Administrators activate from ID Governance > Privileged Identity Management > My roles:
- Select Microsoft Entra roles and find the role.
- Select Activate. If prompted, select Additional verification required and complete MFA.
- Optionally narrow the Scope, set a custom start time, enter the Reason and select Activate.
If approval is required, the request shows as pending until an approver acts. Requests can be tracked and canceled under My requests. PIM adds the active assignment within seconds, but some applications cache whether a user has a role; signing out and back in often makes new permissions visible. When finished, the user can select Deactivate, but not within five minutes of activation.
Step 8: Monitor with alerts and reviews
Browse to ID Governance > Privileged Identity Management > Microsoft Entra roles > Alerts. Key alerts include:
| Alert | Severity | What to do |
|---|---|---|
| Roles are being assigned outside of Privileged Identity Management | High | Find where the assignment came from and remove it |
| Potential stale accounts in a privileged role | Medium | Remove roles from accounts that haven't signed in |
| Administrators aren't using their privileged roles | Low | Remove eligibility that isn't needed |
| Roles don't require multifactor authentication for activation | Low | Require MFA in role settings |
| There are too many Global Administrators | Low | Move people to narrower roles |
Tune thresholds under Alerts > Setting. Schedule access reviews for privileged roles so eligibility is confirmed regularly rather than accumulating.
Verification
- The Active roles tab for each privileged role lists only emergency access accounts and approved exceptions.
- Re-running the inventory query with
assignmentType eq 'Assigned'returns only those accounts;assignmentType eq 'Activated'shows current activations. - A test administrator can activate a role, perform a task, and loses access when the activation ends.
- No Roles are being assigned outside of Privileged Identity Management alert is open.
Troubleshooting
The user isn't prompted for MFA at activation. They already authenticated with strong credentials or did MFA earlier in the session. Use a Conditional Access authentication context with sign-in frequency Every time if you need a fresh check.
The authentication context policy doesn't apply. It is probably scoped to the directory role. Scope it to all users or the eligible users and target the authentication context.
The role is active but the admin portal still says access denied. Some applications cache whether a user has a role, so access doesn't change immediately. Signing out and back in often helps.
An eligible role doesn't appear when querying through Graph. The filterByCurrentUser request for eligibility schedule requests doesn't return eligibility that comes from group membership.
The admin can't deactivate or remove an assignment. Assignments and activations can't be removed within five minutes of being created.
Nobody can approve Global Administrator activation. All admin roles are eligible, approval is required and no approvers are set. Sign in with an emergency access account, set approvers and review the role settings.
Checklist
- Licenses cover eligible users, approvers and reviewers.
- Two emergency access accounts with permanent active Global Administrator.
- Standing assignments exported and each reviewed for a narrower role.
- Role settings configured: MFA, justification, approval for top roles, expiry for eligible assignments.
- Eligible assignments created and tested before active assignments are removed.
- Azure subscription Owner and User Access Administrator assignments moved to eligible.
- PIM alerts reviewed and access reviews scheduled.
References
- What is Privileged Identity Management?
- Microsoft Entra ID Governance licensing fundamentals
- Configure Microsoft Entra role settings in PIM
- Assign Microsoft Entra roles in PIM
- Activate Microsoft Entra roles in PIM
- Assign Azure resource roles in Privileged Identity Management
- Security alerts for Microsoft Entra roles in PIM
- Manage emergency access admin accounts
- unifiedRoleAssignmentScheduleInstance resource type
- Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance