Group based Pim with two required roles

Delos Santos, Joseph 25 Reputation points
2023-03-03T02:33:32.64+00:00

Hi All,

What is the best way to create a group based PIM with two required roles?

1.Permanent- Global Reader. Group

2.Eligible- Exchange, Teams

Would PIM for groups with role assignable groups work? If so, can someone give a sample that I can follow?

Thanks

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
978 questions
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2023-03-07T11:32:47.64+00:00

    @Delos Santos, Joseph Thank you for reaching out to us, Yes it is possible to achieve your ask via PIM. I have tested the same in my tenant and was able to create the same requirement like you mentioned above.

    User's image

    User's image

    Refer to this article: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-how-to-change-default-settings on how to configure this requirement.

    Let me know if you have any further questions, feel free to post back or if you need any help we can connect offline and configure further on the same.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

  3. Delos Santos, Joseph 25 Reputation points
    2023-03-08T06:58:59.6766667+00:00

    Hi Givary,

    how about assigning memberships? where do I follow that?

    Thanks


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.