Security & identity

Set up Entra Privileged Identity Management for just-in-time admin roles

Replace standing admin access with eligible role assignments in Microsoft Entra PIM: inventory current admins, configure role settings, assign, activate, and monitor Entra and Azure roles.

12 min read
On this page

Microsoft Entra Privileged Identity Management (PIM) removes standing admin access by turning permanent role assignments into eligible ones: an administrator holds no privileges until they activate the role for a limited time, from one to 24 hours, after passing the checks you configure, such as MFA, a justification and an approval. To set it up, inventory who holds privileged roles today, configure the role settings for each role, assign administrators as eligible, remove their active assignments, and keep two emergency access accounts as permanent active Global Administrators. PIM needs Microsoft Entra ID P2 or Microsoft Entra ID Governance licenses for the people it governs.

Who this is for and what you will have

This guide is for identity and security administrators who want to reduce how many accounts hold Global Administrator, Exchange Administrator, Azure Owner and similar roles at any moment. It covers Microsoft Entra roles in detail and Azure resource roles more briefly. At the end you will have:

  • An inventory of standing (active) privileged assignments and who holds them.
  • Role settings that require MFA, a justification and, for the most sensitive roles, approval.
  • Administrators converted from active to eligible assignments.
  • A tested activation process and PIM alerts that tell you when roles are assigned outside PIM.

PIM works best on top of strong authentication. If you haven't required MFA for all users yet, start with the Microsoft 365 MFA rollout plan. Just-in-time admin access is also one of the building blocks of a zero trust access architecture.

Key concepts

TermMeaning
EligibleThe user must activate the role before using it. Activation can require MFA, a justification or approval.
ActiveThe user has the role's permissions without doing anything.
PermanentThe assignment has no end date.
Time-boundThe assignment has a start and end date.
ActivateThe process an eligible user follows to use the role for a limited period.

Eligible and active assignments grant exactly the same permissions once active. The difference is only whether the person has them all the time. PIM also prevents removal of the last active Global Administrator and Privileged Role Administrator assignments.

Licensing and permissions

You need Microsoft Entra ID P2 or Microsoft Entra ID Governance licenses for:

  • Users with eligible or time-bound assignments to Microsoft Entra or Azure roles managed in PIM.
  • Users with eligible or time-bound assignments as members or owners in PIM for Groups.
  • Users who approve or reject activation requests.
  • Users assigned to an access review, and users who perform access reviews.

Microsoft's own licensing example: if 14 administrators are managed through PIM and three other people can approve activations, you need 17 licenses. Count everyone in these categories before you start. Microsoft Entra ID P2 is included in Microsoft 365 E5.

To manage assignments for Microsoft Entra roles you need the Privileged Role Administrator role (or Global Administrator). For Azure resource roles you need Owner or User Access Administrator on the resource, or to be a subscription administrator.

Prerequisites

  • Licensing in place as above.
  • Two cloud-only emergency access accounts with phishing-resistant authentication (FIDO2 passkey or certificate-based authentication), excluded from Conditional Access policies that block sign-in.
  • MFA registered by every administrator who will activate roles.
  • Microsoft Graph PowerShell (Microsoft.Graph.Identity.Governance module) for the inventory step.
  • An agreed list of approvers for the highest-privilege roles, with at least two per role.

Step 1: Inventory standing privileged access

In the Microsoft Entra admin center, browse to ID Governance > Privileged Identity Management > Microsoft Entra roles > Roles, open each privileged role and review the Active roles tab. Anything listed there that isn't an emergency access account is a candidate to convert.

For the whole tenant at once, list active assignment instances with Microsoft Graph PowerShell. AssignmentType is Assigned for standing assignments and Activated for roles someone activated through PIM:

Connect-MgGraph -Scopes 'RoleAssignmentSchedule.Read.Directory'
 
$standing = Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -All `
    -Filter "assignmentType eq 'Assigned'" -ExpandProperty roleDefinition
 
$standing | Select-Object PrincipalId,
    @{n='Role';e={$_.RoleDefinition.DisplayName}},
    MemberType, StartDateTime, EndDateTime |
    Sort-Object Role | Export-Csv .\standing-role-assignments.csv -NoTypeInformation

MemberType shows whether the assignment is Direct, Group or Inherited, and EndDateTime shows whether and when it ends. Resolve each PrincipalId to a user, group or service principal and decide, per person, which role they actually need. Replacing Global Administrator with a narrower role such as Exchange Administrator or User Administrator is often a bigger win than PIM itself.

Step 2: Configure role settings

Role settings (also called PIM policies) are defined per role, and every assignment to that role follows them.

  1. Sign in to the Microsoft Entra admin center as at least a Privileged Role Administrator.
  2. Browse to ID Governance > Privileged Identity Management > Microsoft Entra roles > Roles.
  3. Select the role, then Role settings, then Edit.
  4. Configure the settings below and select Update.
SettingWhat it controls
Activation maximum durationMaximum hours an activation lasts, from one to 24
On activation, requireMicrosoft Entra multifactor authentication, or a Conditional Access authentication context
Require justification on activationUser must enter a business reason
Require ticket information on activationUser must enter a ticket number (not validated against any system)
Require approval to activateSelected approvers must approve each activation
Allow permanent eligible assignment / Expire eligible assignment afterWhether eligible assignments can be permanent
Allow permanent active assignment / Expire active assignment afterWhether active assignments can be permanent
Require multifactor authentication on active assignmentAdmin must do MFA when creating an active assignment
Require justification on active assignmentAdmin must give a reason when creating an active assignment
NotificationsWho receives emails for assignments, activations and approvals

A practical starting point is to require MFA and a justification on every role, require approval for Global Administrator and Privileged Role Administrator, keep activation short for the most powerful roles, and expire eligible assignments so they are reviewed. Adjust to your operating model. PIM raises a Roles are being activated too frequently alert when a user activates the same role several times within a set period; Microsoft treats that as a possible sign of attack, so review those users and also check that the activation duration is long enough for their tasks.

Avoid an approval lockout

If every Global Administrator and Privileged Role Administrator assignment is eligible, approval is required, and no approvers are configured, nobody can approve activations and you're locked out. When no approvers are selected, active Privileged Role Administrators and Global Administrators are the default approvers. Always name specific approvers and keep your emergency access accounts permanently active.

Step 3: Require a Conditional Access authentication context (optional)

The On activation, require multifactor authentication setting may not prompt a user who already did MFA in the session. To force stronger checks at activation, for example a phishing-resistant method or a compliant device, use an authentication context:

  1. Create an authentication context in Conditional Access.
  2. Create a Conditional Access policy that targets that authentication context, includes all users or the eligible users, and requires an authentication strength. To force reauthentication on every activation, set sign-in frequency to Every time under Session controls.
  3. Enable that policy, then select the authentication context under On activation, require in the role settings.

Don't scope this policy to the directory role itself. During activation the user doesn't have the role yet, so a role-scoped policy wouldn't apply. If you also want requirements while the role is in use, create a second policy that targets the directory roles. After a user reauthenticates for one activation, a 10-minute window applies across Microsoft Entra roles, Azure resource roles and PIM for Groups.

Create and enable the Conditional Access policy before configuring the context in PIM. If no policy targets the context, PIM falls back to requiring MFA, but that fallback doesn't apply if the policy is off, in report-only mode or excludes the user.

Step 4: Assign eligible roles

  1. Browse to ID Governance > Privileged Identity Management > Microsoft Entra roles > Roles and select Add assignments.
  2. Select Select a role, choose the role and the member (user or group), and select Next.
  3. Set Assignment type to Eligible.
  4. Choose permanent or set start and end dates for a time-bound assignment, then select Assign.

Assignments can't be shorter than five minutes and can't be removed within five minutes of being created. For roles that support it, you can restrict the scope to an administrative unit from Entra ID > Roles & admins instead of granting the role tenant-wide.

You can also create eligible assignments with Microsoft Graph by posting to roleManagement/directory/roleEligibilityScheduleRequests with the action adminAssign.

Step 5: Remove the standing assignments

When each administrator has an eligible assignment and has tested activation, remove the active one:

  1. Open the role in Microsoft Entra roles > Roles.
  2. On the Active roles tab, find the assignment and select Remove.

You can't remove the last active Global Administrator assignment. That is why the emergency access accounts must stay permanently active: they become the active Global Administrators that let everyone else be eligible.

Step 6: Bring Azure resource roles into PIM

Azure Owner, Contributor and User Access Administrator assignments on subscriptions are just as sensitive as directory roles.

  1. Sign in as at least a User Access Administrator on the resource.
  2. Browse to ID Governance > Privileged Identity Management > Azure resources.
  3. Select a management group or subscription, then Select to open it.
  4. Under Manage, select Roles, then Add assignments.
  5. Choose the role and member, set Assignment type to Eligible on the Settings tab, set the duration and select Assign.

Azure resource roles have their own role settings, defined at the resource scope rather than tenant-wide. If you are designing subscription access for a larger migration, the enterprise Azure cloud migration playbook covers how landing zones and management groups shape where these assignments belong.

Step 7: Activate a role

Administrators activate from ID Governance > Privileged Identity Management > My roles:

  1. Select Microsoft Entra roles and find the role.
  2. Select Activate. If prompted, select Additional verification required and complete MFA.
  3. Optionally narrow the Scope, set a custom start time, enter the Reason and select Activate.

If approval is required, the request shows as pending until an approver acts. Requests can be tracked and canceled under My requests. PIM adds the active assignment within seconds, but some applications cache whether a user has a role; signing out and back in often makes new permissions visible. When finished, the user can select Deactivate, but not within five minutes of activation.

Step 8: Monitor with alerts and reviews

Browse to ID Governance > Privileged Identity Management > Microsoft Entra roles > Alerts. Key alerts include:

AlertSeverityWhat to do
Roles are being assigned outside of Privileged Identity ManagementHighFind where the assignment came from and remove it
Potential stale accounts in a privileged roleMediumRemove roles from accounts that haven't signed in
Administrators aren't using their privileged rolesLowRemove eligibility that isn't needed
Roles don't require multifactor authentication for activationLowRequire MFA in role settings
There are too many Global AdministratorsLowMove people to narrower roles

Tune thresholds under Alerts > Setting. Schedule access reviews for privileged roles so eligibility is confirmed regularly rather than accumulating.

Verification

  • The Active roles tab for each privileged role lists only emergency access accounts and approved exceptions.
  • Re-running the inventory query with assignmentType eq 'Assigned' returns only those accounts; assignmentType eq 'Activated' shows current activations.
  • A test administrator can activate a role, perform a task, and loses access when the activation ends.
  • No Roles are being assigned outside of Privileged Identity Management alert is open.

Troubleshooting

The user isn't prompted for MFA at activation. They already authenticated with strong credentials or did MFA earlier in the session. Use a Conditional Access authentication context with sign-in frequency Every time if you need a fresh check.

The authentication context policy doesn't apply. It is probably scoped to the directory role. Scope it to all users or the eligible users and target the authentication context.

The role is active but the admin portal still says access denied. Some applications cache whether a user has a role, so access doesn't change immediately. Signing out and back in often helps.

An eligible role doesn't appear when querying through Graph. The filterByCurrentUser request for eligibility schedule requests doesn't return eligibility that comes from group membership.

The admin can't deactivate or remove an assignment. Assignments and activations can't be removed within five minutes of being created.

Nobody can approve Global Administrator activation. All admin roles are eligible, approval is required and no approvers are set. Sign in with an emergency access account, set approvers and review the role settings.

Checklist

  • Licenses cover eligible users, approvers and reviewers.
  • Two emergency access accounts with permanent active Global Administrator.
  • Standing assignments exported and each reviewed for a narrower role.
  • Role settings configured: MFA, justification, approval for top roles, expiry for eligible assignments.
  • Eligible assignments created and tested before active assignments are removed.
  • Azure subscription Owner and User Access Administrator assignments moved to eligible.
  • PIM alerts reviewed and access reviews scheduled.

References

Questions people ask

What license does Privileged Identity Management need?

Microsoft Entra ID P2 or Microsoft Entra ID Governance. Licenses are needed for users with eligible or time-bound assignments, for users who approve activation requests, and for users assigned to or performing access reviews. Make sure the directory has enough of these licenses to cover every one of those users.

How long can an activated role stay active?

The Activation maximum duration setting is configured per role and can be from one to 24 hours. The user picks a duration up to that maximum when activating, and can deactivate early, but not within five minutes of activation.

Should emergency access accounts be eligible in PIM?

No. Microsoft's guidance is to make the Global Administrator assignment for emergency access accounts active and permanent, not eligible, so the accounts work even when activation or approval isn't possible.

What happens to PIM if the license expires?

Eligible assignments are removed, active time-bound assignments become active permanent, and the PIM blades, APIs and PowerShell interfaces stop working for activation and management. Permanent active assignments are unaffected, so keep licensing current.

Entra PIMMicrosoft Entra IDAzure RBACEntra ID P2Conditional Access
  1. AADSTS50076, 50079 and 50158: fix Microsoft Entra MFA sign-in errors

    What AADSTS50076, AADSTS50079 and AADSTS50158 mean, how to find the policy that demanded MFA in the Entra sign-in logs, and how to fix each one for users, scripts and federated domains.

  2. AADSTS53003 blocked by Conditional Access: find the policy and fix it

    Troubleshoot AADSTS53003 in Microsoft Entra ID: trace the correlation ID to the sign-in log, identify the blocking Conditional Access policy, and fix the user, device or policy without weakening security.

  3. Block legacy authentication in Microsoft 365 without breaking printers

    Find every device and app that still signs in with legacy authentication, move printers and scanners to a supported sending method, then block legacy auth with Conditional Access.