Skip to content
Entra ID Lab

Phase 9 of 11

Privileged Identity Management

Overview

What was built

A permanently active Global Administrator assignment means a compromised account has unlimited admin access forever. Making the role Eligible instead limits the blast radius: even a compromised account has no active admin rights until someone actually goes through PIM's activation workflow, which requires a justification and generates an audit trail every single time.

How it works

The walkthrough

Step 1 of 2

Configuring and testing just-in-time activation

Converted the admin account's Global Administrator assignment to Eligible, with a maximum activation duration of four hours and justification required on every activation. Four hours is enough for almost any real admin task while keeping the window an attacker could exploit deliberately short.

Activated the role once with the justification "Testing PIM activation for Stark Enterprise lab," confirmed full admin access while active, then manually deactivated it to test that workflow too. Every step, the eligible assignment, the activation request, the completed activation, and the deactivation, was captured in the audit log with a timestamp, making the entire elevation traceable end to end.

Global Administrator role activated through Privileged Identity Management with a justification
Just-in-time activation of Global Administrator, logged with a justification.

Step 2 of 2

Why justification but not approval

Justification creates a paper trail for every elevation without adding friction that would slow down legitimate admin work. A second-approver requirement would be appropriate in a production environment with multiple admins, but is impractical in a single-admin lab, so justification alone was the right control for this environment.

PIM audit log showing the full activation and deactivation history
Audit log capturing requestor, timestamp, and justification for every elevation.