M365Clarity · PIM & Roles

Microsoft 365 Privileged Identity Management (PIM) — just-in-time admin access

M365Clarity · 20 June 2026

← All articles

What is Privileged Identity Management?

Privileged Identity Management (PIM) is a feature of Microsoft Entra ID P2 that lets you configure admin roles as eligible rather than permanently assigned. When a user needs to perform an admin task, they activate their eligible role, do the work, and the elevated access expires automatically after a time limit you define — typically 1 to 8 hours.

The benefit is that your admins have near-zero standing privilege in normal operation. If an account is compromised, the attacker doesn't automatically inherit global admin access — they'd need to activate it through PIM, which triggers alerts and can require justification and approval.

What M365Clarity checks

The PIM & Roles tab shows you how many of your privileged role assignments are permanent versus eligible. It highlights any Global Administrator or other high-privilege roles assigned permanently where PIM eligibility would be more appropriate, and identifies users with both permanent and eligible assignments for the same role.

Licence note: PIM requires Microsoft Entra ID P2 or Microsoft Entra ID Governance, included in Microsoft 365 E5 and Business Premium. It's not available on E3 or Business Basic without an add-on.

Setting up PIM

PIM is configured in the Microsoft Entra admin centre under Identity Governance → Privileged Identity Management. You convert permanent role assignments to eligible assignments, configure activation settings (require justification, require MFA, set maximum duration), and optionally require approval from a second admin before activation. Microsoft recommends starting with Global Administrator and working through other high-privilege roles.

Monitoring PIM activations

Every PIM activation is logged in Entra audit logs. You can set up alerts to notify when high-privilege roles are activated outside of normal business hours or from unexpected locations — an early indicator of compromise or insider risk.

See this in action on your tenant

M365Clarity scans your Microsoft 365 configuration and shows you exactly what's in your plan, what's configured, and what's sitting idle — in plain English.

Start free scan →   View live demo

Related articles