implementing-azure-ad-privileged-identity-management
CommunityEnforce just-in-time privileged access in Entra ID
Software Engineering#azure#entra-id#microsoft-graph#just-in-time#pim#access-review#privileged-identity-management
AuthorAcczdy
Version1.0.0
Installs0
System Documentation
What problem does it solve?
This Skill helps eliminate standing privileged assignments by implementing Microsoft Entra Privileged Identity Management (PIM) so that administrators must activate roles just-in-time with MFA, approvals, and time-bound sessions to reduce risk and improve auditability.
Core Features & Use Cases
- PIM Configuration & Hardening: Convert permanent role assignments to eligible assignments, enforce activation duration limits, require MFA and justification, and enable approval workflows for critical roles.
- Automation & Audit: Use Microsoft Graph API scripts to create eligible assignments, activate roles, list role definitions and activations, and generate PIM coverage and compliance reports.
- Governance & Reviews: Schedule recurring access reviews, configure alerts for risky role states, and map settings to compliance frameworks such as NIST and CIS.
- Use Case: Secure a cloud tenant by converting Global and Security Administrators to eligible assignments, enforcing MFA and approvals, and running quarterly access reviews with SIEM forwarding.
Quick Start
Configure Azure Entra PIM to convert permanent admin assignments to eligible roles with 8-hour activation windows, require MFA and approval for Global Admins, and schedule quarterly access reviews.
Dependency Matrix
Required Modules
requestsmsal
Components
scriptsreferencesassets
💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: implementing-azure-ad-privileged-identity-management Download link: https://github.com/Acczdy/MoZiSec/archive/main.zip#implementing-azure-ad-privileged-identity-management Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.