How to migrate all Entra users from static access to PIM?

Neel Darji 86 Reputation points
2024-04-21T15:47:27.91+00:00

I want to implement PIM for all users who are assigned Entra AD roles as permanent assignments. Now I need to implement PIM so that these active role assignments can be converted to PIM eligible. How can I do that? Is there any auto or APIs available for the same or any parameters in UI using which I can convert to PIM eligible roles assignments without changing any existing scope?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,796 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Babafemi Bulugbe 1,955 Reputation points MVP
    2024-04-21T21:59:44.9833333+00:00

    Hello Neel Darji,

    Thank you for posting this in the Microsoft Q&A Community.

    From my understanding, you would like to know how to automate PIM deployment for all users with assigned roles within your organization.

    The best way to do this is to create groups and assign PIM to the groups. Follow this link to get more information

    https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/groups-assign-member-owner

    However, please be informed that when deploying PIM in a production environment, it is best to have a proper plan before doing so. It is not a best practice to implement PIM or deploy PIM for all users at once.

    There are a few things to plan for; how many approvals, how many users will be assigned eligible roles, and how long you want users to keep the role (in the form of the usage windows before they need to make a new request).

    Kindly follow the link https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-deployment-plan to get more information on how to Plan a Privileged Identity Management deployment and also this link https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-getting-started to get started with PIM.

    Let me know if further assistance is required.

    Babafemi