Entra Privileged Identity Management: Engineering Zero Standing Access

October opens with identity depth, starting where the blast radius is biggest: privileged access. The Conditional Access post established the principle that standing privilege is the enemy; Privileged Identity Management is the machinery that eliminates it, and today is the full engineering treatment.

The Model: Eligible, Active, Time Bound

PIM manages three assignment dimensions for Entra roles and Azure RBAC roles alike. Eligibility means you may activate the role; activation means you hold it now, for a bounded duration; and both eligibility and activation carry expiry. The target state for a mature tenant: zero permanent active assignments on privileged roles, eligibility granted to groups rather than individuals, activation windows of one to eight hours depending on role sensitivity, and activation requirements scaled to risk, MFA for everything, justification always, ticket number for production touching roles, and approval by a second human for Global Administrator, Privileged Role Administrator, and the Azure Owner role on production subscriptions.

resource "azurerm_role_management_policy" "sub_owner" {
  scope    = data.azurerm_subscription.prod.id
  role_definition_id = data.azurerm_role_definition.owner.id

  active_assignment_rules {
    expire_after = "P15D"
  }

  eligible_assignment_rules {
    expiration_required = true
    expire_after        = "P180D"
  }

  activation_rules {
    maximum_duration = "PT4H"
    require_multifactor_authentication = true
    require_justification              = true
    require_approval                   = true
    approval_stage {
      primary_approver {
        object_id = azuread_group.pim_approvers.object_id
        type      = "Group"
      }
    }
  }
}

resource "azurerm_pim_eligible_role_assignment" "platform_owner" {
  scope              = data.azurerm_subscription.prod.id
  role_definition_id = data.azurerm_role_definition.owner.id
  principal_id       = azuread_group.platform_admins.object_id

  schedule {
    expiration {
      duration_days = 180
    }
  }
}

PIM for Groups: The Scaling Pattern

Assigning PIM per role per person collapses under its own administration. PIM for groups inverts it: a group carries a bundle of role assignments (the on call platform engineer set: Contributor here, Key Vault Secrets Officer there, AKS RBAC Cluster Admin on the production clusters), and users are eligible for group membership. One activation, one approval flow, one audit trail, granting the whole working set for the shift. It also reaches where role PIM cannot: activating into a group that is assigned to applications, granting time bound access to third party systems that only understand group membership. Model your operational personas as PIM groups and the access model starts matching how people actually work.

Running It: Reviews, Alerts, and the Culture Part

PIM ships access reviews: quarterly attestation of who remains eligible, with auto removal on non response, which converts access sprawl from a permanent condition into a decaying one. Enable the built in alerts, roles assigned outside PIM, activations without use, too many Global Administrators, and route them into the Sentinel pipeline from September. Watch the audit log for activation patterns: a role activated daily at 9 AM by the same person is a workflow that needs a service identity or a delegated permission, not a human ritual, and each one you fix shrinks both friction and attack surface. The cultural objection, activation is annoying, is answered with tuning rather than surrender: sub minute activation for low risk roles with no approval, approvals reserved for the roles where a second pair of eyes is genuinely proportionate, and the break glass accounts from the Conditional Access post standing outside PIM entirely for the day the approval chain itself is the outage. Standing access is a convenience the estate pays for continuously; PIM converts it into a cost paid only at use, visibly, with receipts.

Cheers
Osama

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.