Skip to main content

Privileged Identity Management

Microsoft Entra Privileged Identity Management (PIM) turns a standing role assignment into an eligible one: the role is held only after the person activates it, for a limited time, with a reason. The Azure Enterprise Baseline uses it for the admin roles of its access matrix behind one switch, enable_pim.

What it does​

An eligible assignment names a principal, a role and a scope, like an ordinary role assignment, but grants nothing until it is activated. Activation creates a temporary active assignment that ends after the requested duration. A role management policy per role and scope sets the rules for activation: maximum duration, multifactor authentication, justification, ticket information and optional approval by named approvers, plus notifications. PIM needs Microsoft Entra ID P2 (or Entra ID Governance) for every user who holds an eligible assignment.

How BuiltForProd uses it​

The switch sits in the stack file of environments/core/identity/global:

Azure/acme-azure-platform-baseline/environments/core/identity/global/terragrunt.stack.hcl (lines 19-21)
locals {
enable_pim = false # @optional: true turns Owner / Security Admin into PIM-eligible assignments (Entra ID P2, ~$9/user/month)
}

It is off by default and both identity units read the same value, so an admin role is either standing or eligible, never both:

  • Off: entra-rbac adds the admin map to the standing assignments: Owner and Security Admin at mg-acme for Platform Leads, Owner at mg-acme-plat for DevOps Leads. The pim unit creates nothing.
  • On: entra-rbac leaves the admin map out, and the pim unit (modules/pim/main.tf) creates the eligible assignments and their policies.
Eligible assignmentGroupScopeApproval on activation
OwnerACME_PlatformLeadsmg-acmenone
Security AdminACME_PlatformLeadsmg-acmenone
OwnerACME_BreakGlassmg-acmenone
OwnerACME_DevOpsLeadseach of the four stage subscriptionsa Platform Lead, on acme-plat-prod only

Every activation policy sets a maximum of 12 hours (max_activation_duration = "PT12H"), requires multifactor authentication and a justification, and notifies the default recipients plus any mailbox in notification_emails. Approval applies to Owner on the subscriptions listed in approval_required_subscription_names (["prod"]), with ACME_PlatformLeads as the approver group. Eligibility itself never expires; an active admin assignment made by hand outside PIM expires after 90 days.

Other assignments of the matrix stay standing whatever the switch says, including Azure Kubernetes Service RBAC Cluster Admin at mg-acme-plat for the two lead groups; Azure RBAC lists them.

Cost: Entra ID P2 for each eligible user, about $9 per user per month as the stack file states.

Terms you will see​

TermMeaning
Eligible assignmentA role a principal may activate; grants nothing until activated.
ActivationThe time-boxed active assignment a person requests, up to 12 hours here.
Role management policyThe per-role, per-scope rules for activation: multifactor authentication, justification, approval.
Standing assignmentAn always-active role assignment; the admin roles are standing only with PIM off.
enable_pimThe one switch that both identity units read.

Where to read more​