Azure Active Directory (AD) Privileged Access Management (PIM) lets you control, monitor, and manage privileged access. The service supports various Azure cloud resources, Azure AD, and Microsoft Online Services like Microsoft Intune and Microsoft 365.
You can use Azure AD PIM to provision users with just-in-time privileged access to your Azure resources, including those within Azure AD. The service lets you oversee and monitor the actions performed by PIM users via their privileged access to keep your applications secure and meet compliance needs.
Azure AD PIM can also help you limit the number of individuals allowed access to information and resources to minimize the risk of unauthorized access and accidental data loss. However, PIM is not available as part of the free version – the feature requires the P2 premium license.
Related content: Read our guide to Azure AD Premium
Azure AD PIM supports the following roles and permissions:
Here are some key roles and groups you can manage with PIM:
There are two kinds of assignments—active and eligible. Eligible means that the user does not have the role right now but has the ability to activate it to carry out a privileged task.
It’s possible to create start and end times for all assignment types. There are four possible types of assignments:
When granting access via PIM, follow these best practices:
Pathlock Data Sheet
Read how Pathlock’s integration with Microsoft Azure Active Directory provides enterprises with an identity governance solution for SOX, SoD, & others.
To enable PIM:
To enable secure administrator access:
To configure roles in Privileged Identity Management:
Here are definitions of a few key controls:
To assign a PIM role to an administrator:
Note: once this process is complete, the Exchange Administrator role is revoked from the user’s account. In this way, they become a standard user again. However, they are eligible to become an Exchange Administrator again.
To request activation of PIM managed roles:
Pathlock is the leader in Access Governance for business-critical applications. Staying compliant with Sarbanes-Oxley is a critical business requirement, and Pathlock Control helps to automate the compliance process. As a MISA member, Pathlock can bring these capabilities to users of Azure Active Directory, with tight integration between the solutions.
Customers rely on Pathlock to streamline critical processes like fine-grained provisioning, separation of duties, and detailed user access reviews. With Pathlock’s out-of-the-box integration to Azure Active Directory, customers can enjoy the best of both worlds, including:
Interested to learn more about the winning combination of Pathlock and Azure Active Directory? Request a demo today to see the solution in action!
Share