1. Dokumentationen
  2. Cloud
  3. Azure
  4. Tutorials
  5. Privileged Identity Management (PIM)

Dokumentationen

Privileged Identity Management (PIM)

At a Glance

Goals

  1. You are able to explain the basics of PIM.
  2. You are able to request an elevated role via PIM.

Prerequisites

  1. Authorization to request a PIM group is available.

Privileged Identity Management (PIM)

Elevated privileges can be activated independently via PIM. This behavior follows common security standards. By default, the least privileges are used (the so-called Least Privilege Principle) and only increased when the work requires it.

In Azure, there are two types of PIM:

  • PIM-Enabled Groups

    For a set period, a person is added to an Entra Group, through which extended privileges are temporarily granted. A PIM-Enabled Group can only be administered by IT services.

  • PIM for Azure Resource Roles

    For a set period, an Azure resource role with elevated privileges is assigned to a person.

On both paths, extended privileges can be temporarily gained.

Important

The Unibe-Subscription-Owner (mg-unibe) role is assigned by IT services via a PIM-Enabled Group.

Activating PIM-Enabled Groups

  1. The Portal is logged into.

    Azure Portal

  2. Navigate to the PIM-Module. PIM is entered in the search bar and the search result Microsoft Entra Privileged Identity Management is selected.

    PIM-Module

  3. In the PIM-Module, My Roles is selected under Tasks in the left menu.

    PIM My Roles

  4. Groups is selected in the left menu.

    PIM My Roles

  5. In the list of PIM groups, the role assigned to the subscription is activated with Activate.

    PIM My Roles

  6. The activation duration and a justification are entered.

    PIM Azure Role Activation

Activating PIM for Azure Resource Roles

  1. The Portal is logged into.

    Azure Portal

  2. Navigate to the PIM-Module. PIM is entered in the search bar and the search result Microsoft Entra Privileged Identity Management is selected.

    PIM-Module

  3. In the PIM-Module, My Roles is selected under Tasks in the left menu.

    PIM My Roles

  4. Azure Resources is selected in the left menu.

    PIM Azure Resources

  5. All roles that can be requested are listed. The Activate button in the last column of the table is selected.

    PIM My Azure Roles

  6. The activation duration and a justification are entered.

    PIM Azure Role Activation