Configure Entra PIM for just-in-time role activation
This is for developers and engineers who need Entra Privileged Identity Management working without guesswork. You’ll assign an eligible role, set activation rules, activate it from the portal or Microsoft Graph, and verify the role is active end to end.
TL;DR — You want Entra PIM to grant admin access only when needed, then remove it automatically. The fastest path is: verify your tenant has Microsoft Entra ID P2 or a bundle that includes PIM, assign the user as Eligible for the target role in PIM, set activation rules like MFA/justification/duration, then activate the role and confirm it appears under active role assignments. Reading time: ~5 min
Goal
When you finish, a user in your Entra tenant can activate a privileged role on demand through Entra PIM, the activation will require the controls you set (for example MFA, justification, approval, and a maximum duration), and the role will appear as active only for that activation window.
Prerequisites
- A Microsoft Entra tenant with Privileged Identity Management available through Microsoft Entra ID P2 or a bundle that includes it.
- An account with enough rights to manage PIM for the scope you are changing. In practice, use a Privileged Role Administrator or Global Administrator account.
- The target user account already exists in Entra ID.
- The role you want to make just-in-time, for example: Global Reader, User Administrator, Exchange Administrator, or another Entra role.
- A browser that can complete MFA for the admin and target user.
- Optional for API verification: Microsoft Graph PowerShell SDK. Check with:
pwsh -NoLogo -Command "Get-InstalledModule Microsoft.Graph -ErrorAction SilentlyContinue | Select-Object Name,Version"
- Optional for API verification: Azure CLI with the
az restcommand available. Check with:
az version
- The user principal name (UPN) of the target user, for example
alex@example.com.
Steps
Step 1: Confirm PIM is available in the tenant
In the Microsoft Entra admin center, go to:
Identity → Privileged Identity Management
If prompted to onboard or consent, complete the prompt in that page.
What you should see when this succeeds: the PIM landing page opens and shows role management areas such as Microsoft Entra roles.
Step 2: Open Microsoft Entra role management in PIM
In the Microsoft Entra admin center, go to:
Identity → Privileged Identity Management → Microsoft Entra roles
What you should see when this succeeds: tabs or sections for assignments, eligible assignments, active assignments, approvals, and settings for Entra roles.
Step 3: Assign the user as Eligible for the role
Use this exact menu path:
Identity → Privileged Identity Management → Microsoft Entra roles → Assignments → Add assignments
Set these literal values in the form:
- Member type:
User - Select member(s): choose the target user, for example
alex@example.com - Select role: choose the target role, for example
User Administrator - Assignment type:
Eligible - Start time:
Now - End time: choose one of:
Permanentif your policy allows permanent eligibility- or a fixed date if your org requires time-bounded eligibility
Submit the assignment.
What you should see when this succeeds: the user appears under eligible assignments for that role.
Step 4: Set activation rules for the role
Use this exact menu path:
Identity → Privileged Identity Management → Microsoft Entra roles → Roles → <your role> → Settings → Activation
Set literal values according to your policy. A common working baseline is:
- Activation maximum duration (hours):
1 - On activation, require multifactor authentication:
Yes - On activation, require justification:
Yes - Require ticket information:
NoorYeswith your ticketing requirement - Require approval to activate:
Nofor self-service JIT, orYesand add one or more approvers
Save the settings.
What you should see when this succeeds: the settings page saves without validation errors and shows the new activation rules.
Step 5: Activate the role as the target user
Sign in as the target user, then use this exact menu path:
Identity → Privileged Identity Management → My roles → Microsoft Entra roles → Eligible assignments → <your role> → Activate
Enter the literal values required by your settings, for example:
- Duration:
1 hour - Justification:
JIT activation for production user management task - Ticket number: your change or incident ID if required
Submit the activation and complete MFA or approval if prompted.
What you should see when this succeeds: the role moves from eligible to active for the selected duration, or shows Pending approval if approval is enabled.
Step 6: Verify active assignment in the portal
As an admin, use this exact menu path:
Identity → Privileged Identity Management → Microsoft Entra roles → Assignments → Active assignments
Filter by the target user and role.
What you should see when this succeeds: one active assignment row for the user, role, and an end time matching the activation duration.
Step 7: Optional API verification with Microsoft Graph PowerShell
Install the module if needed:
pwsh -NoLogo -Command "Install-Module Microsoft.Graph -Scope CurrentUser"
Connect with the minimum practical scopes for reading role schedules:
pwsh -NoLogo -Command "Connect-MgGraph -Scopes 'RoleEligibilitySchedule.Read.Directory','RoleAssignmentSchedule.Read.Directory','Directory.Read.All'"
List active role assignment schedules for the user:
pwsh -NoLogo -Command "$u=(Get-MgUser -UserId 'alex@example.com').Id; Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -All | Where-Object { $_.PrincipalId -eq $u } | Select-Object RoleDefinitionId,PrincipalId,StartDateTime,EndDateTime,AssignmentType | Format-Table -AutoSize"
Typical output shape:
RoleDefinitionId PrincipalId StartDateTime EndDateTime AssignmentType
---------------- ----------- ------------- ----------- --------------
62e90394-69f5-4237-9190-012177145e10 11111111-2222-3333-4444-555555555555 10/1/2026 9:00:12 AM 10/1/2026 10:00:12 AM Activated
What you should see when this succeeds: one row with AssignmentType showing an activated assignment and the expected end time.
Verify it works
Run one of these checks end to end.
Portal check:
Identity → Privileged Identity Management → My roles → Microsoft Entra roles
Expected result: the role is listed under Active assignments until the expiry time, then disappears from active assignments after expiry.
Graph PowerShell check:
pwsh -NoLogo -Command "$u=(Get-MgUser -UserId 'alex@example.com').Id; Get-MgRoleManagementDirectoryRoleAssignmentScheduleInstance -All | Where-Object { $_.PrincipalId -eq $u } | Format-Table PrincipalId,RoleDefinitionId,StartDateTime,EndDateTime,AssignmentType -AutoSize"
Expected output shape:
PrincipalId RoleDefinitionId StartDateTime EndDateTime AssignmentType
----------- ---------------- ------------- ----------- --------------
11111111-2222-3333-4444-555555555555 62e90394-69f5-4237-9190-012177145e10 10/1/2026 9:00:12 AM 10/1/2026 10:00:12 AM Activated
If approval is enabled, expected result before approval: the activation request appears in PIM as pending and no active assignment exists yet.
Common pitfalls
Assigned as Active instead of Eligible
Mistake: you create a normal active assignment instead of an eligible assignment in PIM.
Symptom: the user always has the role and never sees an Activate action under My roles.
Fix: delete the active assignment and recreate it with Assignment type: Eligible at Identity → Privileged Identity Management → Microsoft Entra roles → Assignments → Add assignments.
Role settings changed in Entra role management, not in PIM
Mistake: you edit role-related settings outside the PIM role settings page.
Symptom: MFA, justification, approval, or activation duration rules do not apply during activation.
Fix: set the rules at Identity → Privileged Identity Management → Microsoft Entra roles → Roles → <role> → Settings → Activation and save there.
Approval required but no valid approver configured
Mistake: Require approval to activate is enabled without adding approvers who can actually approve.
Symptom: activation stays in Pending approval indefinitely.
Fix: add one or more approvers in the role’s activation settings, then resubmit the activation request.
User is looking in the wrong place to activate
Mistake: the user opens regular role assignments or Azure resource IAM instead of PIM My roles for Entra roles.
Symptom: they cannot find the Activate button even though eligibility exists.
Fix: sign in as the target user and open Identity → Privileged Identity Management → My roles → Microsoft Entra roles.
License or onboarding gap
Mistake: the tenant does not actually have PIM available, or the PIM area was never onboarded.
Symptom: the PIM blade is missing, empty, or prompts for setup instead of showing role management.
Fix: assign the required Entra licensing and open Identity → Privileged Identity Management with a privileged admin account to complete onboarding.
Expecting instant permission propagation in every downstream admin surface
Mistake: you activate the role and immediately test in another portal or workload that caches authorization.
Symptom: PIM shows the role as active, but a downstream admin page still returns authorization errors for a few minutes.
Fix: wait a few minutes, sign out and back in, then retry; verify the active assignment in PIM first before troubleshooting the downstream service.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI