Count your Global Administrators. Now ask how many of them need that access at nine on a Tuesday morning.
Privileged Identity Management turns standing administrative access into access somebody activates when they need it, with an approval, a reason, a multifactor check and a clock. The permissions are identical. What changes is how long they exist and whether anybody can see who used them.

- Just in timeActivated, not held permanently
- Time-boundStart and end dates on assignments
- ApprovalRequired before elevation
- Audit historyDownloadable for internal or external audit
No, you cannot lock yourself out of your own tenant.
It is the first objection every time, and Microsoft has addressed it directly in the product.
- PIM prevents removal of the last active Global Administrator and Privileged Role Administrator role assignments. You cannot reduce your tenant to zero standing administrators by accident, which is the failure mode everybody imagines when the model is first explained.
- Standard practice is still to retain a small number of emergency access accounts excluded from the model, held securely, monitored for use, and tested on a schedule. We set these up as part of any deployment rather than treating them as an afterthought, because an untested break-glass account is not a break-glass account.
- Eligibility is not the same as approval friction. A role can be eligible with no approver and no delay, requiring only a multifactor check and a justification. That configuration alone removes standing privilege and produces an audit trail, and it is a sensible first step before adding approval workflows.
- The rollout order that works is eligibility first with light activation requirements, then approval on the highest roles once people are used to the rhythm, then time-bound assignments and access reviews. Turning everything on at once is how PIM deployments get reversed in week two.
Eight capabilities, and one distinction that explains the whole product.
Eligible versus active, which is the whole idea
Microsoft defines an eligible assignment as one that requires the user to perform one or more actions to use the role, and an active assignment as one that requires no action at all. Then it says the thing that matters: there is no difference in the access given to somebody with a permanent versus an eligible assignment, the only difference is that some people do not need that access all the time. That is the entire product in one sentence.
Just in time and time-bound, which are different things
Just in time means a user activates a role for a limited period and the permissions expire afterwards. Time-bound means the assignment itself has start and end dates, so eligibility for a role ends on a date rather than persisting until somebody remembers. Both are supported and they solve different problems: one limits daily exposure, the other stops a contractor being eligible for anything two years after the project ended.
Approval before elevation
Roles can require approval to activate, with designated approvers who receive email notification, can view pending requests, and can approve or reject them individually or in bulk while providing justification. This is what converts privileged access from something an administrator simply has into something with a second person in the loop, which is what most auditors are actually asking for.
Multifactor authentication at the moment of elevation
Multifactor authentication can be enforced to activate any role, which is a meaningfully stronger control than requiring it only at sign-in. An attacker with a session on an administrator device still faces a check at the moment privilege is used, rather than inheriting whatever the administrator authenticated with hours earlier.
Justification, which creates the record
Users provide a reason when activating, so the audit record contains not just who elevated and when but why they said they needed it. In practice this is one of the most useful outputs, because it makes privileged activity reviewable by somebody who was not present, and it changes behaviour simply by existing.
Notifications when privileged roles are activated
Notification when a privileged role is activated means a Global Administrator elevation is visible to somebody other than the person doing it, in near real time. For a small IT team this is frequently the fastest detection they have of an administrative credential being used by the wrong person, and it costs nothing to configure.
Access reviews, extension and renewal
Access reviews confirm that users still need the roles they hold. Separately, when a time-bound assignment approaches expiry a user can request an extension, and after it expires a renewal, both of which require approval from a Global Administrator or Privileged Role Administrator. That means access expires by default and continues only if somebody actively asks, which is the opposite of the usual arrangement.
Audit history you can hand to an auditor
Audit history is downloadable for internal or external audit. For UAE organisations under Central Bank requirements, an ISO 27001 audit, a SOC 2 examination or a client security questionnaire, this is the artefact that answers the privileged access questions directly, rather than a screenshot of a group membership and an assurance that it is reviewed.
Four things that decide whether PIM survives past week two.
We start with eligibility, not approval
The first phase converts permanent active assignments into eligible ones with a multifactor check and a justification, and no approver. That alone removes standing privilege and creates the audit trail, and it introduces almost no friction. Approval workflows come afterwards, on the roles that genuinely warrant them, once people are used to activating.
We build emergency access properly before we start
Break-glass accounts excluded from the model, credentials held securely, sign-in monitored and alerted, and a test on a schedule so somebody has actually used one before the day it matters. Microsoft prevents removal of the last active Global Administrator, so lockout is not the real risk, but an untested emergency account is a comfort rather than a control.
We include service principals and managed identities
Assignments can be to users, groups, service principals or managed identities, and the non-human ones are almost always the forgotten half. An automation account with permanent Contributor rights on a subscription is exactly the same exposure as a person with permanent rights, and it is less likely to ever be reviewed by anybody.
We configure for the audit you will actually face
If the driver is an ISO 27001 certification, a SOC 2 readiness exercise, a Central Bank expectation or a client questionnaire, the configuration should produce the evidence that specific reviewer asks for. Access reviews on a defined cadence and downloadable audit history covering the review period are the two artefacts that answer most privileged access questions directly.
Six UAE situations where standing privilege is the actual risk.
A regulated firm asked to evidence privileged access control
Banks, finance companies, insurers and DIFC or ADGM entities face direct questions about how administrative access is granted, limited and reviewed. PIM answers all three with product evidence rather than a policy document, and the downloadable audit history is usually the single artefact that closes the finding.
An organisation using an external IT partner
Your partner needs administrative access to do their job and does not need it permanently. Time-bound eligible assignments with approval mean the access exists when work is happening and lapses when it is not, and the audit history shows exactly what was done during each engagement. This is a considerably better arrangement for both sides than a permanent account nobody reviews.
A tenant where nobody knows how many admins there are
The most common starting point. Roles were assigned over years, people changed jobs, projects ended, nothing was removed. The first exercise is simply resolving current privileged assignments including nested groups and non-human identities, and the number is reliably higher than anybody expected.
After a phishing incident involving an administrator
Where an administrative credential was exposed, the immediate question is what that account could reach, and with permanent assignment the answer is everything, instantly. PIM changes the answer for next time, and it is the moment when the operational friction argument stops being persuasive to anybody in the room.
Azure subscriptions with permanent Owner and Contributor
PIM covers Azure resource roles as well as Entra roles, and the Azure side is frequently in worse shape because subscriptions accumulate assignments during projects. Permanent Owner on a production subscription held by somebody who last touched it two years ago is a routine finding, and it is a larger exposure than most of the Entra findings.
An organisation where nothing has ever expired
Time-bound eligibility with extension and renewal changes the default from access persisting forever to access ending unless somebody asks. Both extension and renewal require approval from a Global Administrator or Privileged Role Administrator, so continuation is a decision somebody makes rather than an outcome of nobody looking.
How privileged access is actually held in most UAE tenants.
| Feature | PIM configured | Reviewed occasionally | Permanent assignments |
|---|---|---|---|
Administrative privilege held continuously | No | Yes | Yes |
Approval required before elevation | Yes | No | No |
MFA enforced at the moment of elevation | Yes | No | No |
Reason recorded for each use of privilege | Yes | No | No |
Somebody notified when a role is activated | Yes | No | No |
Assignments expire without action | Yes | No | No |
Access reviews run on administrative roles | Yes | Sometimes | No |
Downloadable audit history for an auditor | Yes | Partial | Partial |
Exposure if an admin account is compromised | Limited | Full | Full |
Frequency in the UAE market | Uncommon | Common | Very common |
The vocabulary, because the conversation is impossible without it.
| Term | What it means | |
|---|---|---|
| Eligible | A role assignment that requires the user to perform one or more actions to use the role | |
| Active | A role assignment that requires no action, the user simply has the privileges | |
| Activate | Performing the actions, which can include an MFA check, a justification, or approval | |
| Permanent eligible | Always eligible to activate the role, with no end date on eligibility | |
| Permanent active | Always holds the role without any action, which is the state most tenants start in | |
| Time-bound eligible | Eligible to activate only within start and end dates | |
| Time-bound active | Holds the role only within start and end dates | |
| Just-in-time access | Temporary permissions granted only when needed, expiring afterwards | |
| Least privilege | Minimum privileges needed for authorised tasks, using specific roles rather than Global Administrator |
Five steps, staged so it does not get reversed.
- 1
Resolve who actually holds privilege today
Every Entra role assignment and every Azure resource role assignment, fully resolved through nested groups, including service principals and managed identities. This inventory is useful in its own right and it is usually the moment the project gets funded, because the number is higher than anybody stated.
- 2
Build and test emergency access
Break-glass accounts excluded from the model, credentials secured, sign-in alerting configured, and an actual test so that somebody has used one before it is needed. This happens before any assignment changes, not after.
- 3
Convert to eligible with light activation requirements
Permanent active assignments become eligible, with multifactor authentication and a justification at activation and a sensible maximum duration, but no approver at first. Standing privilege disappears and the audit trail begins, with minimal disruption to how people work.
- 4
Add approval and time bounds where they earn their place
Approval on the highest roles, with approvers who are genuinely reachable and a documented path for when they are not. Time-bound eligibility for contractors, partners and project access, so that eligibility itself ends on a date rather than persisting indefinitely.
- 5
Set the review rhythm and the audit output
Access reviews on a defined cadence to confirm people still need the roles they hold, notification routing for activations, and a documented process for producing the downloadable audit history when an auditor asks. The last part takes ten minutes to set up and saves a day at audit time.
What organisations ask about Privileged Identity Management.
Fifteen questions worth answering first.
Scope
- How many permanent Global Administrators do you have?The number is almost always higher than the answer given.
- Are Azure resource roles in scope as well as Entra roles?PIM covers both, plus PIM for Groups.
- Do service principals or managed identities hold roles?Assignments can be to users, groups, service principals or managed identities.
- Do any partners or contractors hold administrative roles?The strongest early case for time-bound eligibility.
- Have you confirmed licensing?PIM requires licensing, which we check against your tenant.
Operational reality
- Who approves activation, and are they reachable?An approver on leave becomes an outage.
- What is the maximum activation duration you want?Administrators choose within a maximum you set.
- Do you have emergency access accounts?Excluded, secured, monitored and tested on a schedule.
- Would MFA at activation work for your admins?It is enforceable per role and stronger than sign-in MFA alone.
- Who receives activation notifications?Somebody other than the person elevating.
Audit and governance
- Has anybody asked you to evidence privileged access control?A regulator, an auditor, an insurer or a client.
- Do you run access reviews on administrative roles today?PIM can conduct them rather than a spreadsheet.
- Can you produce a history of who elevated and why?Audit history is downloadable for exactly this.
- Do assignments currently ever expire?In most tenants nothing expires, which is the finding.
- Who reviews the audit history, and how often?Decide before deployment, not at audit time.
The pages around this one.
Access rights review
The wider exercise across all systems, not just Microsoft roles, and the one most audit findings actually ask for.
Active Directory security audit
The on-premises equivalent problem: privileged group membership, delegations and the paths between ordinary and administrative.
Conditional Access
The policy layer that decides the conditions under which any access is granted, administrative or otherwise.
The first number is how many permanent Global Administrators you have.
We resolve that properly, through nested groups and including service principals and managed identities, and in most tenants the answer starts the project on its own. No standing privilege has to change until you decide it should.
Related Services
Explore more solutions that work great with this service
Access Rights Review
Certification that removes access, not one that gets approved
Active Directory Audit
Privilege paths, service accounts and local admin passwords
Entra Conditional Access
The control that decides who reaches your data
Microsoft Entra
Identity and access management solutions
Entra ID P1 vs P2
What P2 genuinely adds, and what quietly moved
IT General Controls
What your external auditor tests, and the evidence they sample
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own