enable Azure PIM for Resources / Resource Group level

NeelDarji-7992 91 Reputation points
2024-02-07T14:44:32.78+00:00

Hello All,

I have couple of questions for Azure PIM:

  1. If I assign 5 PIM enabled roles to any user as Eligible, can they activate each one-by-one? If yes, which role will be most effective among 5? For example, I have Reader role on ABC subscription and Owner role on Management group also inside which I have ABC subscription. If I activate both, will it give me Reader access on ABC subscription or Owner access to Mangement Group?
  2. Same for Entra Roles I have question.
  3. If I want to assign PIM Role to any user to specific resource or resource group level for ABC subscription. Can I achieve that and if yes, how?
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Accepted answer
  1. Navya 20,100 Reputation points Microsoft External Staff Moderator
    2024-02-08T09:42:43.48+00:00

    Hi @Neel Darji

    Thank you for posting this in Microsoft Q&A.

    If I assign 5 PIM enabled roles to any user as Eligible, can they activate each one-by-one? If yes, which role will be most effective among 5? For example, I have Reader role on ABC subscription and Owner role on Management group also inside which I have ABC subscription. If I activate both, will it give me Reader access on ABC subscription or Owner access to Mangement Group?

    Yes, if you assign 5 PIM enabled roles to any user as Eligible, they can activate each one-by-one. If you activate both the Reader role on ABC subscription and the Owner role on the Management group, you will have Owner access to the management group and all the subscriptions under it, including ABC subscription. This is because the Owner role has more permissions than the Reader role, and the management group scope is broader than the subscription scope.

    For your reference: Multiple Role Assignments
    Understand scope for Azure RBAC

    Same for Entra Roles I have question.

    For example, if you have Global Administrator role and Application Administrator Entra role. The Global Administrator role will have higher priority and will grant the user full control over all aspects of Microsoft Entra ID, including application management.

    If I want to assign PIM Role to any user to specific resource or resource group level for ABC subscription. Can I achieve that and if yes, how?

    Yes, you can Assign PIM Role to any user to specific resource or resource group level for ABC subscription.

    Please follow the steps mentioned in the document : Azure resource roles in Privileged Identity Management

    Hope this helps. Do let us know if you any further queries.

    Thanks,

    Navya.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.