Elligible EntraId PIM Assignment only Valid for 1 minute

Cole Duprey 20 Reputation points
2025-05-08T18:22:46.2133333+00:00

In trying to schedule a PIM assignment for Security Admin EntraIa role (which is privileged) it doesnt allow me to set a schedule, say 2 weeks for this role. Any Idea why? Is there some sort of PIM config that would restrict this?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vigneshwar Duvva 2,300 Reputation points Microsoft External Staff Moderator
    2025-05-09T02:17:56.6866667+00:00

    Hello @Cole Duprey

    When you're trying to schedule a PIM assignment for Security Admin EntraIa role (which is privileged) it doesn't allow you to set a schedule for 2weeks.

    Here's an example of the Assignment type tab when you add a role assignment using the Access control (IAM) page. This capability is being deployed in stages, so it might not be available yet in your tenant or your interface might look different.

    User's image

    The assignment type options available to you might vary depending on or your PIM policy. For example, PIM policy defines whether permanent assignments can be created, maximum duration for time-bound assignments, roles activations requirements (approval, multifactor authentication, or Conditional Access authentication context), and other settings. For more information, see Configure Azure resource role settings in Privileged Identity Management.

    Users with eligible and/or time-bound assignments must have a valid license. If you don't want to use the PIM functionality, select the Active assignment type and Permanent assignment duration options. These settings create a role assignment where the principal always has permissions in the role.

    Reference: How to Configure the PIM-functionality

    Hope this helps.

    If this answers your query, do click `Accept Answer` and `Yes`


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.