Forum Discussion
Adding PIM enabled security group to an Access Package
Hi,
A couple of things worth checking here.
First, confirm the group's membership type is Assigned, not Dynamic. Dynamic membership groups only ever expose the Owner role in an access package by design and this holds true even if the group is otherwise PIM enabled. If the test group was created with dynamic membership, that alone explains only seeing 2 roles instead of 4.
Second, being "PIM enabled" for a group is not the same as being fully onboarded to PIM for Groups. The docs describe a specific flow: go to ID Governance > Privileged Identity Management > Groups > Discover groups, select the group, then Manage groups > OK. Only after that step does the group show up in the PIM for Groups managed list and only then does entitlement management expose Member / Owner / Eligible Member / Eligible Owner when you add it as a resource role. If the group was enabled for PIM through a different path (for example directly in the group's own PIM blade rather than through Discover groups), it may not be registered the same way entitlement management expects.
Third, make sure the account adding the resource role has at least Identity Governance Administrator, Catalog owner, or Access package manager permissions on that catalog. Insufficient permissions here usually show as "no available items" rather than 2 vs 4 roles, but worth ruling out.
On licensing: this is not a tenant preview feature you toggle under Identity > Settings > Preview features. It is a licensing gated capability (Entra ID Governance or Entra Suite), so since both your tenants already have one of those, that is not the blocker.
I would recheck the group's membership type first, then confirm it actually appears in the PIM for Groups managed list before touching the access package. That is the most common cause of this exact symptom.