Entra ID PIM Lab: From Standing Admin to Eligible, Approved, and Audited
houssem Makhlouf
0:00 / 0:00
Entra ID PIM Lab: From Standing Admin to Eligible, Approved, and Audited
18 просмотров · 3 дня назад
houssem Makhlouf
1 подписчик
18 просмотров · 3 дня назад
The right number of standing administrators is zero — or two break-glass accounts.
This lab takes a Microsoft Entra ID tenant where a privileged role is held permanently
and turns it into one where the same role is eligible: requested with a justification,
approved by someone else, granted for a bounded time, traced, and reviewed on a schedule.
Everything you see is a real tenant. No slides, no mock-ups.
WHAT YOU'LL DO
• Count the humans holding a privileged role permanently — and understand why that number matters
• Read the PIM grid properly: eligible is not a weaker form of active, it is a different moment
• Convert a standing assignment into an eligible one, with an end date
• Lock the role down: activation duration, MFA, justification, approval
• Request an activation from the user's side, and watch it wait instead of being granted
• Approve it as a second person, reading the justification rather than clicking a button
• Read the audit trail the whole exercise produced
• Schedule a recurring access review over the eligible assignments
CHAPTERS
0:00 Title
0:18 Agenda
0:43 Architecture
0:56 Count the standing administrators
1:27 Open PIM: eligible is not active
1:43 Convert the standing assignment to eligible
2:03 Set the role settings
2:25 Request an activation, from the user's side
3:09 Approve the request
3:41 Read the audit trail
4:08 Schedule a recurring access review
4:53 Wrap-up
WHAT YOU NEED TO FOLLOW ALONG
• Microsoft Entra ID P2 (included in Microsoft 365 E5) — PIM is a P2 feature
• The Privileged Role Administrator role on the account doing the configuration
• Two additional accounts with MFA registered: one requester, one approver
• A demo role that is NOT Global Administrator
THREE THINGS WORTH REMEMBERING
1. A permanently assigned privileged role is a door left open even when nobody walks
through it. The problem is not malice, it is that the exposure window never closes.
2. Converting is not removing. The account keeps its right, it simply stops carrying it
at all times.
3. The break-glass account stays permanent on purpose. Making it eligible would create a
circular dependency: you would need the privilege to repair the system that grants it.
ONE GOTCHA THE LAB SHOWS
PIM role settings open broken when you reach them by deep link — the page half-loads and
its Edit button stays disabled. Go through the settings grid instead. And these settings
are configured role by role: there is no global switch.
MICROSOFT LEARN
• Privileged Identity Management: https://learn.microsoft.com/entra/id-gover...
• Configure Entra role settings in PIM: https://learn.microsoft.com/entra/id-gover...
• Activate Entra roles: https://learn.microsoft.com/entra/id-gover...
• Approve or deny requests: https://learn.microsoft.com/entra/id-gover...
• Access reviews: https://learn.microsoft.com/entra/id-gover...
• Break-glass accounts: https://learn.microsoft.com/entra/identity...
Recorded on a dedicated lab tenant. The narration uses a synthetic voice; the screen
recording, the portal and the results are real and unedited.
#MicrosoftEntra #PIM #IdentityGovernance #Microsoft365 #ZeroTrust