Can I use Azure Just in Time (JIT) RBAC without PIM e.g. as a standalone solution

%3CLINGO-SUB%20id%3D%22lingo-sub-113683%22%20slang%3D%22en-US%22%3ECan%20I%20use%20Azure%20Just%20in%20Time%20(JIT)%20RBAC%20without%20PIM%20e.g.%20as%20a%20standalone%20solution%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-113683%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3C%2FP%3E%3CP%3EI%20saw%20a%20video%20show%20PIM%20(Privilaged%20Access%20Management)%20and%20part%20of%20it%20Showed%20using%20Just%20In%20Time%20administration%20to%20allow%20a%20user%20(after%20MFA%20authentication)%20to%20elevate%20to%20admin%20to%20do%20some%20work%20for%20a%20set%20period%20of%20time).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20need%20to%20know%20more%20about%20JIT%20for%20RBAC%20whereby%20I%20want%20to%20for%20example%20give%20someone%20the%20ability%20to%20elevate%20their%20role%20(to%20contributor%20for%20example)%20via%20MFA%20or%20some%20kind%20of%20admin%20approval%2C%20so%20they%20can%20perform%20a%20task%20then%20their%20contributor%20role%20expires%20(without%20necessarily%20using%20PIM).%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20I%20am%20having%20great%20difficultly%20finding%20vidoes%2C%20documentation%20(prefer%20good%20videos%20if%20available)%20showing%20how%20to%20set%20this%20up%20and%20make%20it%20work%20with%20a%20few%20examples%20and%20what%20level%20of%20Azure%20subscription%20you%20need%20to%20allow%20JIT%20RBAC%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20someone%20please%20advise%20and%20point%20me%20towards%20some%20good%20vidoes%20or%20blog%20articles%20on%20this%20please%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E__AAnotherUser%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-113683%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EJIT%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ERBAC%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-251585%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20I%20use%20Azure%20Just%20in%20Time%20(JIT)%20RBAC%20without%20PIM%20e.g.%20as%20a%20standalone%20solution%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-251585%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%20take%20a%20look%20at%20this%20Pluralsight%20video%20just%20got%20published%20about%20Implementing%20Privileged%20Identity%20Manager%20PIM.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fblog.ahasayen.com%2Fmicrosoft-azure-pim%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblog.ahasayen.com%2Fmicrosoft-azure-pim%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIt%20goes%20in%20great%20details%20and%20show%20to%20to%20enable%20PIM%2C%20configure%20JIT%2C%20time-bound%20access%20and%20permanent%20access%2C%20how%20to%20configure%20access%20reviews%20and%20workflow%20approvals.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello 

I saw a video show PIM (Privilaged Access Management) and part of it Showed using Just In Time administration to allow a user (after MFA authentication) to elevate to admin to do some work for a set period of time).

 

I need to know more about JIT for RBAC whereby I want to for example give someone the ability to elevate their role (to contributor for example) via MFA or some kind of admin approval, so they can perform a task then their contributor role expires (without necessarily using PIM). 

 

However I am having great difficultly finding vidoes, documentation (prefer good videos if available) showing how to set this up and make it work with a few examples and what level of Azure subscription you need to allow JIT RBAC

 

Can someone please advise and point me towards some good vidoes or blog articles on this please

 

Thanks

__AAnotherUser

1 Reply

Hi, take a look at this Pluralsight video just got published about Implementing Privileged Identity Manager PIM. https://blog.ahasayen.com/microsoft-azure-pim/

 

It goes in great details and show to to enable PIM, configure JIT, time-bound access and permanent access, how to configure access reviews and workflow approvals.