Skip to main content
AD Academy
Microsoft Entra ID (Azure AD)
Intermediate10 minLast updated: Topic 4 of 6

PIM made simple: admin rights only when you need them

How Privileged Identity Management works — Eligible vs Active, activation, approval and audit.

Not read

What you will learn here

  • Why standing admin rights are a risk
  • The difference between Eligible and Active
  • What role activation looks like and what gets logged

Worth reading first:Protecting access: Conditional Access, MFA and PIM

In many organizations several people hold Global Administrator around the clock — even while just reading email. Compromise one of those accounts and the attacker owns the whole cloud at once. PIM (Privileged Identity Management) fixes this: the right exists, but stays “switched off” until requested.

Eligible vs Active

  • Eligible — the user may activate the role, but does not hold it right now.
  • Active — the role is on right now, for a limited time (for example, two hours).
  • Permanent Active — exactly what we want to reduce; keep it only for the break-glass account.

What activation looks like

  • The admin opens the PIM portal and picks their role.
  • Enters a reason (for example, a ticket number) and completes MFA.
  • If configured — another manager approves the request.
  • After the set time the role switches off on its own.

Check yourself

What does an Eligible role mean in PIM?

Was this page helpful?