
Direct assignments are permanent and always active, meaning if an attacker manages to compromise your admin user, it gets access to everything (that the admin has access to). With PIM, you get Just in time activation, meaning an admin assignment is not always active, and you can configure additional conditions for activation, such as MFA, or manager approval, etc.
There is detailed documentation here: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure