PIM: force approval workflow to eligible role

Share on facebook
Share on google
Share on twitter
Share on linkedin
Share on pinterest
Share on print
Share on email
Table of Contents

introduction

in previous article : we have seen how to assign eligible privileged role to user , and seen also that user can activate his eligible role by him self without need approval from approver 

this article we will see how to force approval workflow to activate eligible role 

 

when to use approval workflow for eligible role

there are some time you need to configure approval workflow for activation eligible privileged role : 

  • you organization has change management
  • external contractor need  access approval  

PIM approvers license requiremetns

before configure PIM approveal workflow >> we need to know that approvers require one of the following license : 

  • EMS E5
  • Azure AD P2

configure approval work flow for eligible role

first step is to force approval workflow for activation eligible privileged role 

log to azure portal as PIM admin 

then search for PIM 

 

select settings >> the your resource : for example exchange
as you notice : approval is NOT configured for exchange >> select edit
select require approval >> select approvers
select approvers
now exchange resource activation require approval from bisan or ahmad

assign eligible role to user

in previous article we see how to assign eligible role for user abdulla 

now we will assign role to hisham 

login to azure portal 

search for PIM 

select exchange role >> eligible assignment >> add assignment 

add assignmen
now hishma is added as eligible exchange admin
when hisham login to PIM in aure portal >> he will see that he is eligible

approval workflow

 user try to activate role as previous article 

but now user hisham will NOT be able to activate his role with him self 

insead 

activation request  will be sent to approvers ( bisa and ahmad ) 

 

 

 

hishma activate his role
hisham set activation time and reason to user exchange admin center
activation request sent to approvers
activation request sent to approvers
approver bisan see pending request from hisham
bisan approve hisham request to activate his role
request approved and sent to user hisham
request approved and sent to user bisan also

conclusion

PIM  Just in Time (JIT) is great feature  that control access to administrative resources 

when assign eligible privileged role to user >> he can activate his role when needed 

we can configure user to activate his role without need approval from PIM approvers 

OR 

we can force activation to require approval for more control 

next article : we will see how to  configure  time boundary ro PIM role 

 

thank you 

Share this post
Share on facebook
Share on google
Share on twitter
Share on linkedin
Share on pinterest
Share on print
Share on email

About Me

Our Power in Numbers

 17 

Courses

321

Articles

3,882

Images
and All configurations images are proudly made in Pioneers Lab

Articles By Course

Recent Articles

Subscribe

Contact us

have a challenge ? don’t hesitate to contact us