Forum Discussion

Amit_Trivedi112214's avatar
Amit_Trivedi112214
Copper Contributor
Apr 10, 2019

Azure - PIM

Hi,

We have enable PIM for our tenant.

When we enable our role through PIM, how much time does it take to activate that role on that user level ? 

  • Faiza Qadri's avatar
    Faiza Qadri
    Iron Contributor
    Depends if you have additional security measures like 2 factor enabled. It’s a good practice to have PIM based roles to avoid accidents in production but be mindful about any accounts that need elevated permissions in Azure like data analytics or PowerBI those roles need to be assigned prior.
    • Amit_Trivedi112214's avatar
      Amit_Trivedi112214
      Copper Contributor

      Faiza Qadri  Thank you for your answer but what do you mean by assigned Prior. Also the reason of my asking this question is sometimes we see our roles activated in few seconds and sometimes it takes time to activate our privileged roles.

      • Faiza Qadri's avatar
        Faiza Qadri
        Iron Contributor
        I meant that any service accounts that have elevated privileges other than user account privileges would need to be assigned prior. For example you might have a reporting service that uses a service account but is part of the reporting group or user admin group, those roles need to be assigned to them.

        In terms of timing the time varies from 10 secs to about a min (having MFA or 2 factor)