Using Privileged Identity Management
In this tutorial, we will learn and understand about the process of enabling Privileged Identity Management (PIM) and using it.
Use Privileged Identity Management (PIM) for managing, controlling, and monitoring access within your Azure Active Directory (Azure AD) organization. Moreover, with PIM you can provide as-needed and just-in-time access to Azure resources, Azure AD resources, and other Microsoft online services like Office 365 or Microsoft Intune.
Prerequisites
For using PIM, you must have one of the following licenses:
- Firstly, Azure AD Premium P2
- Secondly, Enterprise Mobility + Security (EMS) E5
Preparing PIM for Azure AD roles
After enabling Privileged Identity Management for your directory, you can prepare PIM for managing Azure AD roles.
The tasks we recommend for you to prepare for Azure AD roles, in order:
- Firstly, configuring Azure AD role settings.
- Secondly, giving eligible assignments.
- Thirdly, allowing eligible users to activate their Azure AD role just-in-time.
Preparing PIM for Azure roles
After enabling Privileged Identity Management for your directory, you can prepare PIM for managing Azure roles for Azure resource access on a subscription.
The task we recommend for you to prepare for Azure roles, in order:
- Firstly, discovering Azure resources
- Secondly, configuring Azure role settings.
- Thirdly, giving eligible assignments.
- Lastly, allowing eligible users to activate their Azure roles just-in-time.
Navigating to your tasks
After setting up PIM, you can learn your way around.
Adding a PIM tile to the dashboard
For making it easier to open Privileged Identity Management, add a PIM tile to your Azure portal dashboard.
- Firstly, Sign in to the Azure portal.
- Secondly, select All services and find the Azure AD Privileged Identity Management service.
- Then, select the Privileged Identity Management Quickstart.
- Lastly, check the Pin blade to the dashboard to pin the Privileged Identity Management Quickstart blade to the dashboard.
Reference: Microsoft Documentation