Skip to content
← Back to the guide

Entra ID Privileged Identity Management

8slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 8

Entra ID Privileged Identity Management

PIM turns standing admin access into just-in-time, approval-gated activation. The model, what it covers, role settings that work, and a rollout that sticks.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-privileged-identity-management

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 8
01

What licence is needed for PIM?

Entra ID P2, included in Microsoft 365 E5, E5 Security, and the Entra Suite. Every user who is eligible for or activates a role through PIM needs P2; permanent assignments and users who never activate do not.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-privileged-identity-management

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 8
02

What is the difference between eligible and active in PIM?

An eligible assignment means the user can activate the role on demand (with MFA, justification, and optionally approval) for a limited time. An active assignment means the role is held continuously. PIM's purpose is to…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-privileged-identity-management

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 8
03

Can PIM manage groups and Azure resources too?

Yes. PIM for Groups makes membership or ownership of a group eligible, which is how you make application roles or Intune scope tags just-in-time. PIM for Azure resources does the same for Azure RBAC roles at subscriptio…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-privileged-identity-management

Slide 4Download PNG
M
solvingmicrosoft365.com
5 / 8
04

Tenant-critical

Examples: Global Admin, Privileged Role Admin, Partner Tier2 Support · Max activation: 2 h · MFA at activation: Phishing-resistant (auth context c1) · Justification: Required · Ticket: Required · Approval: Required

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-privileged-identity-management

Slide 5Download PNG
M
solvingmicrosoft365.com
6 / 8
05

Security-critical

Examples: Security Admin, Conditional Access Admin, Authentication Policy Admin · Max activation: 4 h · MFA at activation: Phishing-resistant · Justification: Required · Ticket: Required · Approval: For CA / authenticat…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-privileged-identity-management

Slide 6Download PNG
M
solvingmicrosoft365.com
7 / 8
06

Workload admin

Examples: Exchange, SharePoint, Teams, Intune, Compliance · Max activation: 8 h · MFA at activation: Standard MFA · Justification: Required · Ticket: Optional · Approval: No

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-privileged-identity-management

Slide 7Download PNG
M
solvingmicrosoft365.com
8 / 8
07

Governance admin

Examples: Identity Governance, User Admin, Groups Admin · Max activation: 4 h · MFA at activation: Standard MFA · Justification: Required · Ticket: Optional · Approval: For User Admin only

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/entra-id-privileged-identity-management

Slide 8Download PNG

Auto-generated from Entra ID Privileged Identity Management. This page is not indexed and isn't part of the guide itself.