Events
Apr 8, 3 PM - May 28, 7 AM
Sharpen your AI skills and enter the sweepstakes to win a free Certification exam
Register now!This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Use Privileged Identity Management (PIM) to manage, control, and monitor access within your Microsoft Entra organization. With PIM you can provide as-needed and just-in-time access to Azure resources, Microsoft Entra resources, and other Microsoft online services like Microsoft 365 or Microsoft Intune.
This article describes how to enable Privileged Identity Management (PIM) and get started using it.
To use Privileged Identity Management, you must have a Microsoft Entra ID P2 or Microsoft Entra ID Governance license. For more information on licensing, see Microsoft Entra ID Governance licensing fundamentals.
When a Microsoft Entra tenant has a Microsoft Entra ID P2 or Microsoft Entra ID Governance license, users with active role assignments can do the following:
Microsoft Entra enables PIM for the tenant in the following ways:
These behaviors are expected and shouldn't affect your workflows.
Here are the tasks we recommend for you to prepare Privileged Identity Management to manage Microsoft Entra roles:
Here are the tasks we recommend for you to prepare Privileged Identity Management to manage Azure roles for a subscription:
Once Privileged Identity Management is set up, you can learn your way around.
Task + Manage | Description |
---|---|
My roles | Displays a list of eligible and active roles assigned to you. My roles is where you can activate any assigned eligible roles. |
My requests | Displays your pending requests to activate eligible role assignments. |
Approve requests | Displays a list of requests to activate eligible roles by users in your directory that you can approve. |
Review access | Lists active access reviews you are assigned to complete, whether you're reviewing access for yourself or someone else. |
Microsoft Entra roles | Displays a dashboard and settings for Privileged Role Administrators to manage Microsoft Entra role assignments. This dashboard is disabled for anyone who isn't a Privileged Role Administrator. These users have access to a special dashboard titled My view. The My view dashboard only displays information about the user accessing the dashboard, not the entire organization. |
Groups | Manage just-in-time membership in the group or just-in-time ownership of the group. Groups can be used to provide access to Microsoft Entra roles, Azure roles, and various other scenarios. To manage a Microsoft Entra group in PIM, you must bring it under management in PIM. |
Azure resources | Displays a dashboard and settings for Privileged Role Administrators to manage Azure resource role assignments. This dashboard is disabled for anyone who isn't a Privileged Role Administrator. These users have access to a special dashboard titled My view. The My view dashboard only displays information about the user accessing the dashboard, not the entire organization. |
General settings | Select applications that are allowed to make app-only calls to Microsoft Graph API for PIM. |
Events
Apr 8, 3 PM - May 28, 7 AM
Sharpen your AI skills and enter the sweepstakes to win a free Certification exam
Register now!