azureblog.co.uk
← cd ~/learn
azureblog.co.uk · cheat sheet

Privileged Identity Management (PIM)

Eligible versus active roles, activation settings, the three things PIM can manage, and the commands you'll actually use.

Fits on one A4 page. Checked 9 Oct 2026.

Assignment types

  • Eligible: the user can activate the role when needed. This is the default for admins.
  • Active: the role is in effect now. Time-bound if it has an end date, permanent if not.
  • Permanent active: keep for break-glass accounts only.

PIM manages Entra roles, Azure resource roles (management group, subscription, resource group, resource) and groups (membership or ownership, through PIM for Groups).

Activation settings (per role)

  • Maximum activation duration, up to 24 hours
  • Require MFA, or a Conditional Access authentication context (stronger)
  • Require a justification and, optionally, ticket details
  • Require approval, with named approvers
  • Notifications to admins and approvers when roles are assigned or activated

A sensible baseline

  • Fewer than five Global Administrators, all eligible, none permanent
  • Approval for Global Administrator and Privileged Role Administrator
  • Authentication context with phishing-resistant MFA on activation
  • Short activation (one to four hours) for high-impact roles
  • Two break-glass accounts as the only permanent Global Admins
  • Quarterly access reviews of eligible assignments

Licensing

Users who benefit from PIM need Entra ID P2 or Entra ID Governance. P2 is included in Microsoft 365 E5. Check the licence finder for your plan.

Good to know

  • After activation, sign out and back in (or wait a few minutes) if the portal doesn't show the new rights.
  • Deactivate when you're done: it shortens the window for a stolen session.

PowerShell

# List your eligible Entra roles
Get-MgRoleManagementDirectoryRoleEligibilityScheduleInstance -Filter "principalId eq '$myId'" -ExpandProperty RoleDefinition

# Activate one (selfActivate) for two hours
New-MgRoleManagementDirectoryRoleAssignmentScheduleRequest -BodyParameter @{ Action = "selfActivate"; PrincipalId = $myId; RoleDefinitionId = $roleId; DirectoryScopeId = "/"; Justification = "Change 1234"; ScheduleInfo = @{ StartDateTime = Get-Date; Expiration = @{ Type = "AfterDuration"; Duration = "PT2H" } } }

# Azure resource roles use Az PowerShell
New-AzRoleAssignmentScheduleRequest -Name (New-Guid) -Scope "/subscriptions/" -RoleDefinitionId $azRoleId -PrincipalId $myId -RequestType SelfActivate -Justification "Change 1234" -ExpirationType AfterDuration -ExpirationDuration PT2H

Guides: activating PIM roles from PowerShell and requiring an authentication context on activation.