What is difference between Directly assigning the admin privilege and via PIM?

Vinod Survase 4,776 Reputation points
2023-08-30T13:36:58.28+00:00

What is difference between Directly assigning the admin privilege and via PIM?

For example: I assigned any admin access in M365 directly and another admin access via PIM so what would be difference in both and what are the benefits of each?

Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Vasil Michev 119.6K Reputation points MVP Volunteer Moderator
    2023-08-30T15:44:03.5766667+00:00

    Direct assignments are permanent and always active, meaning if an attacker manages to compromise your admin user, it gets access to everything (that the admin has access to). With PIM, you get Just in time activation, meaning an admin assignment is not always active, and you can configure additional conditions for activation, such as MFA, or manager approval, etc.

    There is detailed documentation here: https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-configure


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.