Skip to content

PIM Operations — Privileged Identity Management

Purpose: Day-to-day operations for Privileged Identity Management (PIM) in Entra ID PROD and DDE tenants.

Owner: Rory Audience: Rory, Kevin, Greg (break-glass approval path) Review frequency: Quarterly alongside compliance/annual-review-checklist.mdLast reviewed: May 2026

The exclusion list (accounts permanently outside PIM) is in compliance/pim-exclusion-list.md. This document covers operations.


Overview

All privileged Entra roles in PROD (tenant d477c9f8) and DDE (tenant ff1c5d68) are eligible assignments activated through PIM — not permanent active assignments. The same applies to Azure RBAC Owner, Contributor, and User Access Administrator at subscription scope.

Humans elevate via PIM. Service principals and managed identities have scoped permanent assignments reviewed quarterly via runbooks/quarterly-sp-permission-review.md.


Activating a Role

Portal path: Entra → Identity Governance → Privileged Identity Management → My roles → Eligible assignments

  1. Find the role you need to activate
  2. Click Activate
  3. Set the activation duration. Standard maximum is 4 hours. If you need longer, justify it in the reason field
  4. Enter a business justification: be specific (e.g., "Deprovisioning terminated user JD-12345" not just "admin work")
  5. If MFA prompt appears: complete with FIDO2 token (preferred) or Microsoft Authenticator
  6. Click Activate — activation takes 30–60 seconds
  7. Refresh My roles → Active assignments to confirm the role is active

Duration policy:

RoleMax DurationNotes
Global Administrator1 hourOnly for cross-tenant or break-glass work
Privileged Role Administrator1 hourPolicy changes only
User Administrator4 hoursStandard provisioning work
Security Administrator4 hoursCA policy changes
Exchange / SharePoint / Teams Administrator4 hoursStandard
Azure RBAC Owner (any subscription)2 hoursInfrastructure work under CM

Roles That Require Approval

Some roles require a second-person approval before activation completes:

  • Global Administrator — Rory approves
  • Privileged Role Administrator — Rory approves

If Rory is unavailable (travel, emergency), Kevin or Greg can approve for break-glass situations. They receive the approval request via email and via Entra PIM notification.

Approval steps (for approver):

  1. Entra → Identity Governance → PIM → Approve requests
  2. Review the requester, role, justification, and duration
  3. Approve or deny with a note

MFA Requirement

PIM activation always requires MFA. No exceptions.

Preferred: FIDO2 hardware key (YubiKey). Required for Global Admin and Privileged Role Admin activations.

Acceptable: Microsoft Authenticator push notification for lower-privilege roles.

If MFA fails during activation: do not attempt to bypass. Verify the device is registered in Entra → My Security Info. If the FIDO2 key is not working, use Authenticator as a fallback for non-global-admin roles only.


Audit and Monitoring

PIM audit logs: Entra → Identity Governance → Privileged Identity Management → Audit log

Rory reviews PIM activations weekly as part of the monthly security review (runbooks/monthly-security-review.md).

SecOps alert: Any PIM activation outside business hours (07:00–19:00 PST) triggers a SecOps alert. Check whether the activation was expected before closing the finding. If the activation is legitimate, create a known-good rule scoped to the specific account and role with a 24-hour expiry.

What to look for in the audit log:

  • Activations by accounts that should not have eligible assignments
  • Activations at unusual hours without a CM ticket
  • Approvals that were self-approved (policy violation — Rory must not approve his own activations)
  • Repeated failed activation attempts (possible credential testing)

Quarterly Access Review

Every quarter, coordinate with compliance/annual-review-checklist.md:

  1. Export all eligible PIM assignments: Entra → PIM → Manage → Roles → each role → Eligible assignments → export
  2. For each eligible assignment: confirm the user still requires the role for their current job function
  3. Eligible assignments not activated in the last 90 days are candidates for removal — confirm with Rory before removing
  4. Document the review outcome in the SecOps quarterly review record

Revoking a Role Activation Early

If a role needs to be revoked before the activation window expires:

  1. Entra → Identity Governance → PIM → Active assignments
  2. Find the active assignment
  3. Click Deactivate

Or from the user's session: Entra → My roles → Active assignments → Deactivate


Adding a New Eligible Assignment

All new eligible assignments require Rory's approval. Never add eligible assignments without Rory's sign-off.

  1. Entra → PIM → Manage → Roles → [role] → Assignments → Add assignments
  2. Select member, set assignment type to Eligible, set expiry if appropriate
  3. Document the justification in the assignment notes

PIM Exclusions

Accounts that hold permanent active assignments (excluded from PIM) are documented and justified in compliance/pim-exclusion-list.md. That list is reviewed quarterly. If you discover a human account with a permanent active privileged role assignment that is not on the exclusion list, report it to Rory — it is a policy violation.


  • compliance/pim-exclusion-list.md — accounts excluded from PIM with justifications
  • runbooks/conditional-access-reference.md — Conditional Access policies enforcing MFA
  • runbooks/quarterly-sp-permission-review.md — service principal permission reviews
  • runbooks/break-glass-procedure.md — break-glass account procedures
  • compliance/annual-review-checklist.md — quarterly review checklist

Internal use only — Cirius Group