Mar 16 2022
04:21 PM
- last edited on
Feb 10 2023
02:36 PM
by
TechCommunityAP
Mar 16 2022
04:21 PM
- last edited on
Feb 10 2023
02:36 PM
by
TechCommunityAP
Can PIM be used for membership of a plain security group? We have a Sass application configured with SSO using Azure AD and admin roles in Sass app are controlled via an Azure AD security group. This security group does not have any Azure AD or Azure roles assigned.
Could we use PIM to assign group membership of this security group as Eligible? Up-on activation, admins will then become active members of the group and get JIT access to Sass app.
Mar 17 2022 01:14 AM
Jun 13 2022 04:39 AM
SolutionHave you checked 'Privileged Access groups'?
You can set up just-in-time access to permissions and roles beyond Azure AD and Azure Resource. If you have other resources whose authorization can be connected to an Azure AD security group (for Azure Key Vault, Intune, Azure SQL, or other apps and services), you should enable privileged access on the group and assign users as eligible for membership in the group.
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/groups-featur...
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/concept-privi...
Jun 13 2022 04:39 AM
SolutionHave you checked 'Privileged Access groups'?
You can set up just-in-time access to permissions and roles beyond Azure AD and Azure Resource. If you have other resources whose authorization can be connected to an Azure AD security group (for Azure Key Vault, Intune, Azure SQL, or other apps and services), you should enable privileged access on the group and assign users as eligible for membership in the group.
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/groups-featur...
https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/concept-privi...