Phase 9 of 11
Privileged Identity Management
Overview
What was built
A permanently active Global Administrator assignment means a compromised account has unlimited admin access forever. Making the role Eligible instead limits the blast radius: even a compromised account has no active admin rights until someone actually goes through PIM's activation workflow, which requires a justification and generates an audit trail every single time.
How it works
The walkthrough
Step 1 of 2
Configuring and testing just-in-time activation
Converted the admin account's Global Administrator assignment to Eligible, with a maximum activation duration of four hours and justification required on every activation. Four hours is enough for almost any real admin task while keeping the window an attacker could exploit deliberately short.
Activated the role once with the justification "Testing PIM activation for Stark Enterprise lab," confirmed full admin access while active, then manually deactivated it to test that workflow too. Every step, the eligible assignment, the activation request, the completed activation, and the deactivation, was captured in the audit log with a timestamp, making the entire elevation traceable end to end.

Step 2 of 2
Why justification but not approval
Justification creates a paper trail for every elevation without adding friction that would slow down legitimate admin work. A second-approver requirement would be appropriate in a production environment with multiple admins, but is impractical in a single-admin lab, so justification alone was the right control for this environment.
