How to Protect Internal Admin Tools With Privileged Identity Management
Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.
Microsoft Entra Privileged Identity Management (PIM) makes administrative access temporary, approved and audited. Here is how to use it to protect admin roles and internal tools.
Step 1: Discover privileged assignments
In the Entra admin center, open Identity governance → Privileged Identity Management → Microsoft Entra roles and review permanent assignments. Also review Azure resource roles (Owner, Contributor, User Access Administrator) and privileged groups.
Step 2: Convert permanent to eligible
For each admin (except break-glass accounts), change permanent assignments to eligible. Admins then activate roles when needed.
Step 3: Configure role settings
For highly privileged roles (Global Administrator, Privileged Role Administrator, Security Administrator, Exchange Administrator):
- Activation maximum duration: 1–4 hours.
- Require MFA on activation — use Conditional Access authentication context to require phishing-resistant MFA.
- Require justification and, for the most sensitive roles, approval.
- Notifications to security staff on activation.
Step 4: Protect custom internal tools
For internal admin applications, use Entra app roles or groups and manage membership with PIM for Groups, so access to internal tools is also just-in-time.
Step 5: Run access reviews
Schedule quarterly access reviews of eligible assignments so roles are removed when people change jobs.
Step 6: Monitor
Alert on activations outside business hours, activations without tickets, and new eligible or permanent assignments.
Verify
The number of permanent privileged assignments should be close to zero (break-glass accounts only).