introduction
PIM enable you to control to use administrative roles
just in time ( JIT ) is one of PIM approach that allow you to reduce the of compromising your Cloud organization
this article we will discuss how to use JIT to control privileged administrative role effectively
how JIT works
JIT works in the following scenario
- PIM admin (who is normally is global admin like bisan@pioneers101.onmicrosoft.com ) assign eligible role to normal user who need role to perform administrative task
- this role is eligible for specific period of time ( for example 1 moth )
- during this month user will still be normal user
- when user need to perform administrative task >> he will activate this privileged for small mount of time ( for example 1 hour )
- after 1 hour (activation period ) >> user will back as normal user without privileged role >> but he can activate this again when needed
- after assignment period ( 1 month ) : user will NOT be able to activate privileged role since assignment period expired
- user can request to extend assignment period from 1 month to more time ( 3 month) as need which need approve from PIM admin
step 02- user activate his eligible role
now user abdulla is eligible to activate role
user abudlla lig to azure portal and search for PIM
before activate eligible role >> user must enable MFA to protect his identity
now user can activate his eligible role
how to verify if eligible role activated
there is so many place to verify if eligible role has been activated
- PIM admin will receive notification email
- user will also receive notification email
- PIM admin can check from PIM role to see which eligible activated
- also user will see
- exchange admin center EAC in his office.com
deactivate eligible role
let us to say that user abdulla@netwrokspioneers.com has finish his administrative tasks before activation time expired ( before one hour )
simply
he can deactivate role >> and back as normal user without any privileged role
extend eligible role
user Abdulla feel that assignment period ( one month ) is NOT enough and request from basin ( as PIM admin ) to extend period 2 weeks more ( until 15-jan-2021 )
conclusion
as we see above
user was able to activate his eligible role without need approval from PIM admin
next article : we will how to force user to get approval from PIM admin when activate his eligible role
please keep tuned