Перейти к содержимому

Entra ID PIM Lab: From Standing Admin to Eligible, Approved, and Audited

houssem Makhlouf

0:00 / 0:00

Entra ID PIM Lab: From Standing Admin to Eligible, Approved, and Audited

18 просмотров · 3 дня назад
houssem Makhlouf
1 подписчик
18 просмотров · 3 дня назад
The right number of standing administrators is zero — or two break-glass accounts. This lab takes a Microsoft Entra ID tenant where a privileged role is held permanently and turns it into one where the same role is eligible: requested with a justification, approved by someone else, granted for a bounded time, traced, and reviewed on a schedule. Everything you see is a real tenant. No slides, no mock-ups. WHAT YOU'LL DO • Count the humans holding a privileged role permanently — and understand why that number matters • Read the PIM grid properly: eligible is not a weaker form of active, it is a different moment • Convert a standing assignment into an eligible one, with an end date • Lock the role down: activation duration, MFA, justification, approval • Request an activation from the user's side, and watch it wait instead of being granted • Approve it as a second person, reading the justification rather than clicking a button • Read the audit trail the whole exercise produced • Schedule a recurring access review over the eligible assignments CHAPTERS 0:00 Title 0:18 Agenda 0:43 Architecture 0:56 Count the standing administrators 1:27 Open PIM: eligible is not active 1:43 Convert the standing assignment to eligible 2:03 Set the role settings 2:25 Request an activation, from the user's side 3:09 Approve the request 3:41 Read the audit trail 4:08 Schedule a recurring access review 4:53 Wrap-up WHAT YOU NEED TO FOLLOW ALONG • Microsoft Entra ID P2 (included in Microsoft 365 E5) — PIM is a P2 feature • The Privileged Role Administrator role on the account doing the configuration • Two additional accounts with MFA registered: one requester, one approver • A demo role that is NOT Global Administrator THREE THINGS WORTH REMEMBERING 1. A permanently assigned privileged role is a door left open even when nobody walks through it. The problem is not malice, it is that the exposure window never closes. 2. Converting is not removing. The account keeps its right, it simply stops carrying it at all times. 3. The break-glass account stays permanent on purpose. Making it eligible would create a circular dependency: you would need the privilege to repair the system that grants it. ONE GOTCHA THE LAB SHOWS PIM role settings open broken when you reach them by deep link — the page half-loads and its Edit button stays disabled. Go through the settings grid instead. And these settings are configured role by role: there is no global switch. MICROSOFT LEARN • Privileged Identity Management: https://learn.microsoft.com/entra/id-gover... • Configure Entra role settings in PIM: https://learn.microsoft.com/entra/id-gover... • Activate Entra roles: https://learn.microsoft.com/entra/id-gover... • Approve or deny requests: https://learn.microsoft.com/entra/id-gover... • Access reviews: https://learn.microsoft.com/entra/id-gover... • Break-glass accounts: https://learn.microsoft.com/entra/identity... Recorded on a dedicated lab tenant. The narration uses a synthetic voice; the screen recording, the portal and the results are real and unedited. #MicrosoftEntra #PIM #IdentityGovernance #Microsoft365 #ZeroTrust