Microsoft Entra Privileged Identity Management (PIM) - formerly Azure Active Directory PIM enables a more secure, manageable and monitorable approach to assigning privileged permissions in your organization.
PIM enables just-in-time privileged access for users that are eligible for it, reducing the chance of privileged actions being done by malicious (or unaware) actors.
Things that we can do with PIM (taken from What is Microsoft Entra Privileged Identity Management?):
As best practice, your company should use PIM to give access to new SysAdmins.
Do the following:
✅ Figure: Good example - Assigning roles in PIM
✅ Figure: Good example - Having the option of Eligible and Active makes PIM flexible
You are now assigned roles in PIM.
If you are eligible for assignments, you can activate them by doing the following:
✅ Figure: Good example - Activate just-in-time roles only when you need it
You now have that role active for you, for up to 8 hours.
PIM has built-in alerts that will send an email when assignments are activated, together with its justification, who activated it, the role activated, and extra information:
✅ Figure: Good example - PIM emails you when assignments and roles are activated, you can see straight away if something's wrong!