We want to send weekly report over a email to Management for resource audit functionality in PIM

Siva Poreddy 1 Reputation point
2023-01-09T08:49:26.43+00:00

We want to send weekly report over a email to Management for resource audit functionality in PIM Azure AD. The requirement is if for certain subscription , suppose "X" number users activated their access through PIM. So, need the report of "X" number of users with details like when they have activated and till what time , duration of activation etc.

Regards,

Microsoft Entra
{count} votes

1 answer

Sort by: Most helpful
  1. Shweta Mathur 27,456 Reputation points Microsoft Employee
    2023-01-09T14:12:51.503+00:00

    Hi @Siva Poreddy ,

    Thanks for reaching out.

    You can extract the report for Azure resources roles in Privileged Identity Management using:

    Navigate to Azure AD Privileged Identity Management and select the resource you want to view activity.

    Select the user from Roles to view full detail of each user.

    277465-image.png

    To provide complete list of role assignments to auditors. PIM allow to query all active and eligible role assignments in a subscription by selecting Assignments and exports all members details like member type, assignment start date and end date time.

    277486-image.png

    Reference: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/azure-pim-resource-rbac

    Hope this will help.

    Thanks,
    Shweta


    Please remember to "Accept Answer" if answer helped you.

    0 comments No comments