In PIM I have disallowed permanent active assignment for a group, but in AAD I can add the a permanent group member

Andy Knifton 20 Reputation points
2023-09-13T10:33:08.29+00:00

I've set a group in PIM to not allow permanent active assignment but when I add a user to the group in AAD, the user is assigned permanent active membership. This doesn't seem right.

I'm trying to configure the group so active membership can only be assigned for a certain time period (ideally 4 hours). Does anyone know a way of doing this?

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2023-09-13T11:56:54.3033333+00:00

    With groups you can use this feature:

    This will make them only eligible. I use this and works as expected:

    https://learn.microsoft.com/en-us/azure/active-directory/privileged-identity-management/concept-pim-for-groups


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.