Loading...

Just-in-time access to groups and Conditional Access integration in Privileged Identity Management

Just-in-time access to groups and Conditional Access integration in Privileged Identity Management

As part of our mission to enable customers to manage access with least privilege, we’re excited to announce the general availability of two additions to Microsoft Entra Privileged Identity Management (PIM): PIM for Groups and PIM integration with Conditional Access.

 

Just-in-time access to privileged roles with PIM for groups

 

Part of Microsoft Entra ID Governance and Microsoft Entra ID P2, PIM enables you to manage just-in-time access to privileged roles in Microsoft Entra, Microsoft 365 services, and Azure.


With the new just-in-time group membership capability, you can now further simplify least privilege access by enabling just-in-time access for all resources that support security group or Microsoft 365 group assignments. This includes support for a wide range of roles such as Microsoft Entra roles, Azure resource roles, Microsoft Intune and non-Microsoft application roles and services. IT admins, developers, and security experts can now activate group membership once and have access to all defined resources precisely when needed to do their job.

 

PIM for Groups supports:

 

  • Just-in-time group membership and ownership. Members get access to various resources through the group membership, while owners can manage group properties such as membership.
  • Role-assignable and non-role-assignable groups, which removed the previous limit of 500 groups managed in PIM.
  • Security and Microsoft 365 group types.

 

sdriggers_0-1695923337279.png

 

 

 

Learn more about PIM for Groups: Privileged Identity Management (PIM) for Groups - Microsoft Entra | Microsoft Learn

 

Enforce security requirements for activation using PIM integration with Conditional Access

 

Conditional Access authentication context allows you to apply granular policies to sensitive data and actions, going beyond app-level policies. By combining PIM with Conditional Access, you can now enforce specific requirements for PIM role activations, enhancing your security posture. During public preview, customers have leveraged this integration for various scenarios, such as:  

 

  • Requiring strong modern authentication methods, using Conditional Access Authentication Strengths.
  • Requiring a compliant device for role activation.
  • Validating the user’s location through GPS-based named locations.
  • Blocking activation for risky users using Microsoft Entra ID Protection.

 

sdriggers_1-1695832914780.png

 

 

 

The PIM and Conditional Access integration is available for all providers: PIM for roles, PIM for Azure resources, and PIM for groups.

 

Configure authentication context requirements within PIM policies:

 

 

sdriggers_2-1695832914795.png

 

 

Eligible users must meet verification requirements during role:

 

sdriggers_4-1695833258999.png

 

Check out the documentation to learn more about Conditional Access authentication context.

 

Learn more about configuring Conditional Access authentication context in PIM settings at the links below:

 

 

Joseph Dadzie
Partner Director of Product Management

LinkedIn: @joedadzie
Twitter: @joe_dadzie

 

 

Learn more about Microsoft Entra:

Published on:

Learn more
Azure Active Directory Identity Blog articles
Azure Active Directory Identity Blog articles

Azure Active Directory Identity Blog articles

Share post:

Related posts

Sync identities from Rippling to Microsoft Entra ID

Today, we’re thrilled to announce that customers using Rippling HCM can now automatically provision users to on-premises Active Directory and ...

1 year ago

Microsoft Entra ID Governance for government

I’m pleased to announce that as of November 1, 2024, Microsoft Entra ID Governance is available for federal agencies, state and local governme...

1 year ago

Update to security defaults

As part of the Secure Future Initiative, we’ve evolved our security approach to align with three security principles: secure by design, secure...

1 year ago

Meet Microsoft Entra at Ignite 2024: November 18-22

Microsoft Ignite is just around the corner, taking place from Monday, November 18, 2024 through Friday, November 22, 2024, in Chicago, Illinoi...

1 year ago

Manage Microsoft Entra ID role assignments with Microsoft Entra ID Governance

I’m excited to announce that we now support Microsoft Entra role assignments in Microsoft Entra ID Governance's Entitlement Management feature...

1 year ago

The latest enhancements in Microsoft Authenticator

Hi folks,   I'm thrilled to announce three major Microsoft Entra ID advancements that will help you protect your users with phishing-resi...

1 year ago

Microsoft Security announcements and demos at Authenticate 2024

The Microsoft Security team is excited to connect with you next week at Authenticate 2024 Conference, taking place October 14 to 16 in Carlsba...

1 year ago

What's new in Microsoft Entra - September 2024

We’re excited to announce the general availability of Microsoft Entra Suite—one of the industry’s most comprehensive secure access solutions f...

1 year ago

Explore the key benefits of Microsoft Entra Private Access

The traditional network security models are becoming increasingly ineffective in a world where remote work and cloud services are the norm. Co...

1 year ago

Join us at the Microsoft Entra Suite Showcase!

This fall, we are bringing the Microsoft Entra Suite Showcase to cities worldwide. Join us to explore how our latest advancements in secure id...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.