Forum Discussion
Adding PIM enabled security group to an Access Package
Hi,
A couple of things worth checking here.
First, confirm the group's membership type is Assigned, not Dynamic. Dynamic membership groups only ever expose the Owner role in an access package by design and this holds true even if the group is otherwise PIM enabled. If the test group was created with dynamic membership, that alone explains only seeing 2 roles instead of 4.
Second, being "PIM enabled" for a group is not the same as being fully onboarded to PIM for Groups. The docs describe a specific flow: go to ID Governance > Privileged Identity Management > Groups > Discover groups, select the group, then Manage groups > OK. Only after that step does the group show up in the PIM for Groups managed list and only then does entitlement management expose Member / Owner / Eligible Member / Eligible Owner when you add it as a resource role. If the group was enabled for PIM through a different path (for example directly in the group's own PIM blade rather than through Discover groups), it may not be registered the same way entitlement management expects.
Third, make sure the account adding the resource role has at least Identity Governance Administrator, Catalog owner, or Access package manager permissions on that catalog. Insufficient permissions here usually show as "no available items" rather than 2 vs 4 roles, but worth ruling out.
On licensing: this is not a tenant preview feature you toggle under Identity > Settings > Preview features. It is a licensing gated capability (Entra ID Governance or Entra Suite), so since both your tenants already have one of those, that is not the blocker.
I would recheck the group's membership type first, then confirm it actually appears in the PIM for Groups managed list before touching the access package. That is the most common cause of this exact symptom.
Thanks for your answer.
This question is from last year and occured on my lab tenant.
I havent touched that configuration in a year and tested it now. Now, I do get the expected 4 roles.
So either it was a bug, or a timing issue longer than a week (?) back then.
Created another group, discovered it in PIM. added to a catalog and access package.
Immediately get all 4 role options. so it now works as expected.
Cheers.