Privileged Identity Management
Microsoft Entra Privileged Identity Management (PIM) turns a standing role assignment into an eligible one: the role is held only after the person activates it, for a limited time, with a reason. The Azure Enterprise Baseline uses it for the admin roles of its access matrix behind one switch, enable_pim.
What it does
An eligible assignment names a principal, a role and a scope, like an ordinary role assignment, but grants nothing until it is activated. Activation creates a temporary active assignment that ends after the requested duration. A role management policy per role and scope sets the rules for activation: maximum duration, multifactor authentication, justification, ticket information and optional approval by named approvers, plus notifications. PIM needs Microsoft Entra ID P2 (or Entra ID Governance) for every user who holds an eligible assignment.
How BuiltForProd uses it
The switch sits in the stack file of environments/core/identity/global:
locals {
enable_pim = false # @optional: true turns Owner / Security Admin into PIM-eligible assignments (Entra ID P2, ~$9/user/month)
}
It is off by default and both identity units read the same value, so an admin role is either standing or eligible, never both:
- Off:
entra-rbacadds theadminmap to the standing assignments: Owner and Security Admin atmg-acmefor Platform Leads, Owner atmg-acme-platfor DevOps Leads. Thepimunit creates nothing. - On:
entra-rbacleaves theadminmap out, and thepimunit (modules/pim/main.tf) creates the eligible assignments and their policies.
| Eligible assignment | Group | Scope | Approval on activation |
|---|---|---|---|
| Owner | ACME_PlatformLeads | mg-acme | none |
| Security Admin | ACME_PlatformLeads | mg-acme | none |
| Owner | ACME_BreakGlass | mg-acme | none |
| Owner | ACME_DevOpsLeads | each of the four stage subscriptions | a Platform Lead, on acme-plat-prod only |
Every activation policy sets a maximum of 12 hours (max_activation_duration = "PT12H"), requires multifactor authentication and a justification, and notifies the default recipients plus any mailbox in notification_emails. Approval applies to Owner on the subscriptions listed in approval_required_subscription_names (["prod"]), with ACME_PlatformLeads as the approver group. Eligibility itself never expires; an active admin assignment made by hand outside PIM expires after 90 days.
Other assignments of the matrix stay standing whatever the switch says, including Azure Kubernetes Service RBAC Cluster Admin at mg-acme-plat for the two lead groups; Azure RBAC lists them.
Cost: Entra ID P2 for each eligible user, about $9 per user per month as the stack file states.
Terms you will see
| Term | Meaning |
|---|---|
| Eligible assignment | A role a principal may activate; grants nothing until activated. |
| Activation | The time-boxed active assignment a person requests, up to 12 hours here. |
| Role management policy | The per-role, per-scope rules for activation: multifactor authentication, justification, approval. |
| Standing assignment | An always-active role assignment; the admin roles are standing only with PIM off. |
enable_pim | The one switch that both identity units read. |
Where to read more
- Azure Enterprise Baseline overview for the identity subscription.
- Conditional Access for the sign-in rules that apply before any activation.
- Least privilege for why admin rights are time-boxed.