Entra ID & IdentityHow-To & HardeningRetrospectives

How to Protect Internal Admin Tools With Privileged Identity Management

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

Microsoft Entra Privileged Identity Management (PIM) makes administrative access temporary, approved and audited. Here is how to use it to protect admin roles and internal tools.

Step 1: Discover privileged assignments

In the Entra admin center, open Identity governance → Privileged Identity Management → Microsoft Entra roles and review permanent assignments. Also review Azure resource roles (Owner, Contributor, User Access Administrator) and privileged groups.

Step 2: Convert permanent to eligible

For each admin (except break-glass accounts), change permanent assignments to eligible. Admins then activate roles when needed.

Step 3: Configure role settings

For highly privileged roles (Global Administrator, Privileged Role Administrator, Security Administrator, Exchange Administrator):

  • Activation maximum duration: 1–4 hours.
  • Require MFA on activation — use Conditional Access authentication context to require phishing-resistant MFA.
  • Require justification and, for the most sensitive roles, approval.
  • Notifications to security staff on activation.

Step 4: Protect custom internal tools

For internal admin applications, use Entra app roles or groups and manage membership with PIM for Groups, so access to internal tools is also just-in-time.

Step 5: Run access reviews

Schedule quarterly access reviews of eligible assignments so roles are removed when people change jobs.

Step 6: Monitor

Alert on activations outside business hours, activations without tickets, and new eligible or permanent assignments.

Verify

The number of permanent privileged assignments should be close to zero (break-glass accounts only).

entra privileged identity managementTwitter admin tool hack2020

More on this story