In many organizations several people hold Global Administrator around the clock — even while just reading email. Compromise one of those accounts and the attacker owns the whole cloud at once. PIM (Privileged Identity Management) fixes this: the right exists, but stays “switched off” until requested.
Eligible vs Active
- Eligible — the user may activate the role, but does not hold it right now.
- Active — the role is on right now, for a limited time (for example, two hours).
- Permanent Active — exactly what we want to reduce; keep it only for the break-glass account.
What activation looks like
- The admin opens the PIM portal and picks their role.
- Enters a reason (for example, a ticket number) and completes MFA.
- If configured — another manager approves the request.
- After the set time the role switches off on its own.