Unable to Recreate the Azure PIM event

Raghuram Chandrasekaran 5 Reputation points
2023-08-12T06:21:14.24+00:00

Audit Logs of Azure AD contains the following PIM Activities(Events). The workflow or the activity which creates the events are not known.

  • Add eligible member to role in PIM canceled (permanent)
  • Add eligible member to role in PIM canceled (renew)
  • Add eligible member to role in PIM canceled (timebound)
  • Add member to role in PIM canceled (permanent)
  • Add member to role in PIM canceled (renew)
  • Add member to role in PIM canceled (timebound)
  • Add member to role in PIM requested (renew)

Could anyone point me to any references or methods to create the event?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
24,277 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,191 Reputation points Microsoft Employee
    2023-08-15T20:51:25.7566667+00:00

    @Raghuram Chandrasekaran ,

    PIM activities automatically generate many logs when actions are taken in PIM (adding or removing members). The ones you listed are all related to PIM activities that were canceled or requested. If you filter by the Audit Category, you can check for related activities. For example, the GroupManagement category will query "Add member to role in PIM canceled (permanent).

    User's image

    If your goal is to recreate the PIM events you listed, could you please provide more information on what you would like to achieve and what you have tried so far?

    The events should get generated by performing the actions described (canceling the role addition or requesting to add a member to a role). The list of audit activities for PIM is documented here: https://learn.microsoft.com/en-us/azure/active-directory/reports-monitoring/reference-audit-activities#privileged-identity-management-pim

    If the information helped you, please Accept the answer. This will help us as well as others in the community who may be researching similar questions. Otherwise let me know if you have further questions.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.