How to enable PIM for groups using the API

Anonymous
2023-10-10T19:50:44.66+00:00

So you've got a somewhat readable page about how to use the Graph API to integrate with PIM for groups here however that require you to have already pressed the button in the AD group -> Privileged Identity Management -> "Enable pim for this group".

I'm lost in finding the API that does the same as that button, where might you have hidden that ?

Below you can see the button that provides the functionality I'm looking for in an API.

User's image

Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. PatrickMangold-2508 6 Reputation points
    2023-11-21T07:39:50.31+00:00

    Hi @Anonymous ,

    The given answer is incorrect. I was stuck on the same thing with support for a longer time as I did find api calls to enable PIM for groups but they were not officially documented and delivered 401 unknown error when being called by a managed identity (even if the underlying system change worked).

    Anyway, for automation purposes you do not need to send an enablement call. As per document update (2. September 2023) it will automatically enable the group for PIM once you apply the first setting.

    "You can't onboard a group to PIM for groups explicitly. When you request to add assignment to group using Create assignmentScheduleRequest or Create eligibilityScheduleRequest, or you update PIM policy (role settings) for a group using Update unifiedRoleManagementPolicy or Update unifiedRoleManagementPolicyRule, the group is onboarded to PIM automatically if it wasn't onboarded before."
    https://learn.microsoft.com/en-us/graph/api/resources/privilegedidentitymanagement-for-groups-api-overview?view=graph-rest-1.0#onboarding-groups-to-pim-for-groups

    1 person found this answer helpful.
    0 comments No comments

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.