Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Staff intended to have administrative roles in UConn’s Entra ID or Microsoft 365 environments are required to activate their role(s) using PIM. A PIM “Just in time” policy ensures that accounts only hold elevated privileges when while they are necessary to perform administrative tasks.

...

Info

Roles can be activated for up to 8 10 hours at a time.

Steps to Activate

  1. Navigate to https://entra.microsoft.com and login with your NetIDAdmin account.

  2. Expand the Identity Governance section and click on Privileged Identity Management (PIM)

    1. Optionally pin PIM as a favorite by clicking the star icon to the right of its entry.

      left-hand navigation in Microsoft Entra ID highlighting the Privileged Identity Management option in the Identity Governance sectionImage Modified

  3. Click on My roles under the Tasks section on the left-hand side.

    My roles option highlighted in the left-hand navigation of the Privilged Identity Management section of Microsoft Entra ID
  4. Then, click Groups in the Active section.

    The groups section highlighted in the left-hand navigation menu of the groups section
  5. Click Activate next to the role assigned group you wish to active roles for.

If you are responsible for managing a PIM group in your area, you will see an additional Owner role row under Eligible assignments. You can activate this owner role to manage other assignments in that group. Please review Managing "Just in Time" Microsoft Admin Roles via Privileged Identity Management (PIM) for

...

more information on how to do so.

...

  1. Specify a duration and provide a short justification, then click Activate.

    The prompt shown upon activating a role with an example justification and 8 hour time windowImage Modified
  2. Do not navigate away from this screen until the 3 activation steps complete as shown below. The roles associated with your PIM group will be added to your NetIDAdmin account for the duration you specified.

    image-20250102-151055.pngImage Added

...

Child pages (Children Display)
depth1
allChildrentrue
style
pageSeamless Single Sign-On
sortAndReverse
first0