Graph API support for Azure AD PIM Privileged access groups.

Backer, Faris 21 Reputation points
2022-02-04T15:47:49.33+00:00

HI,

Is there any graph api support to create azure ad group with PIM enabled and edit setting for Privileged access groups?

Basicallly we are trying to automate creation of PIM enabled group and edit the setting of Privileged access groups.

Thanks

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Graph
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
    2022-02-04T22:10:19.857+00:00

    @Backer, Faris
    Thank you for your post!

    Using Graph APIs to create an Azure AD Groups with Privileged Identity Management (PIM) enabled, currently isn't supported. Additionally editing settings for Privileged access groups, is only supported through the Azure Portal. The PIM APIs are in public preview and with the current iteration now in beta, the PIM API consists of two categories: Azure AD roles and Azure resource roles: assignment, and activation API requests, and policy settings.

    When it comes to the relationship between PIM entities and role assignment entities, the only link between the PIM entity and the role assignment entity for persistent (active) assignment for either Azure AD roles or Azure roles is the roleAssignmentScheduleInstance. There is a one-to-one mapping between the two entities. For more info.

    If you'd like the ability to be able to create PIM enabled Azure AD groups and edit their settings using the Graph API, I'd recommend leveraging our User Voice forum and creating a feature request, so our engineering team can look into implementing this. I've also created an internal feature request, so our engineering team is aware of this as well.

    Links:
    Understand the Privileged Identity Management APIs
    Bring privileged access groups (preview) into Privileged Identity Management
    Configure privileged access group settings (preview) in Privileged Identity Management

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


  2. CarlZhao-MSFT 46,376 Reputation points
    2022-02-25T07:30:42.897+00:00

    Hi @Backer, Faris

    According to your requirements, I suggest you open a support ticket.


  3. Ketan Siddhapura 0 Reputation points
    2023-09-28T13:22:30.4166667+00:00

    is this feature available now?

    Using Graph API Create azure ad group with PIM enabled and edit setting for Privileged access groups?


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.