Step-by-step interactive guide for activating Privileged Identity Management group memberships via the Azure portal.
With Entra now having the ability for Privileged Identity Management (PIM) associated with security groups, R&R have decided to take advantage of this, allowing you to activate multiple roles at the same time. The new process will allow you to activate certain roles deemed as BAU roles for 8 hours, with the ability to then activate more privileged roles through a second activation.
The new activation process requires you to navigate to the Groups section within PIM. The steps to complete this are outlined below.
In the PIM left-hand navigation panel, under Activate, click on Groups — not "Microsoft Entra roles" or "Azure resources". You will land on the My roles | Groups page showing your eligible group memberships.
R&R now uses PIM for Groups rather than direct role activation. A security group in Entra can be linked to multiple roles simultaneously. By activating at the Group level, you activate all BAU roles assigned to that group in one single action — saving time and reducing the need for repeated individual activations.
Click the Activate link next to your eligible group assignment. In the activation dialog that appears:
A reason is required by PIM to maintain an audit trail explaining why access was requested. Entering "BAU" (Business as Usual) documents that this is a routine activation. The 8-hour time limit enforces the principle of least privilege — access automatically expires so you never hold elevated permissions longer than necessary.
After submitting the activation request, you will be prompted to verify your identity via Multi-Factor Authentication (MFA). Open your phone authenticator app (e.g. Microsoft Authenticator) and approve the sign-in request or enter the one-time passcode shown.
MFA is a critical security control required when activating privileged access. Even if your password were compromised, an attacker cannot activate PIM roles without also having physical access to your phone. This second factor ensures elevated permissions are only granted to the verified, authorised individual — protecting the organisation's entire Azure environment.
Ensure your phone is accessible and your Authenticator app is configured before starting the activation. The MFA prompt may time out if not approved promptly.
If your group membership includes sensitive or highly privileged roles, your activation request will be sent for approval. A second person who is a member of the Approvers group must approve your request before access is granted. Wait for their approval before proceeding.
The four-eyes (dual authorisation) principle is a security best practice for high-risk access requests. Requiring a second person to approve sensitive role activations prevents any single individual from unilaterally gaining access to critical systems — significantly reducing the risk of insider threats, accidental misuse, or compromised accounts obtaining dangerous levels of access without oversight.
Not all activations require approval. Standard BAU role group activations are typically self-approved immediately. Only roles specifically designated as sensitive will trigger the approval workflow. You will receive a notification once approved.
After approval, navigate to My roles → Microsoft Entra roles → Active assignments tab to confirm your roles are now active. They should appear with a Group membership type and Assigned status.
After this initial activation you may also be eligible for additional more privileged roles that can be found in the Roles tab for a second activation if needed.
Verifying your active assignments confirms the PIM activation completed successfully and your Entra ID roles are live. This is important to check before beginning any work requiring elevated permissions — ensuring you won't be blocked mid-task due to a failed or pending activation.
Activation sometimes requires another logon to the Azure portal to view resources. If resources are not immediately visible after activation, open a new browser tab and log back in to the Azure portal.
🎉 Activating the group activates all BAU roles assigned to it in one go!
You may also be able to activate Azure resources, found under the Azure resources tab in PIM. This only applies if your job role requires you to administer Microsoft Azure directly. After logging in, groups associated with Azure resources will appear as eligible assignments. Resources on the old Landing Zone are available here and will be migrated to use PIM for groups as each workload is migrated during the upcoming Azure Optimisation project.
You have successfully activated your PIM roles for groups. Your BAU roles are now active for 8 hours.
Remember: if resources are not immediately visible in the Azure portal, open a new tab and log in again.