Houses of Parliament Restoration & Renewal
Interactive Guide

Activating Roles in PIM for Groups

Step-by-step interactive guide for activating Privileged Identity Management group memberships via the Azure portal.

Version 1 R&R Parliament 2025

ℹ Introduction

With Entra now having the ability for Privileged Identity Management (PIM) associated with security groups, R&R have decided to take advantage of this, allowing you to activate multiple roles at the same time. The new process will allow you to activate certain roles deemed as BAU roles for 8 hours, with the ability to then activate more privileged roles through a second activation.


The new activation process requires you to navigate to the Groups section within PIM. The steps to complete this are outlined below.

Overall Progress0 of 6 steps completed
📋 Activation Process
1
Log on to PIM via the Azure Portal

Navigate to the Azure Portal (portal.azure.com) and sign in with your organisational credentials. Once logged in, search for "Privileged Identity Management" in the search bar and select it.

💡 Why this step?

PIM is Microsoft's solution for managing, controlling, and monitoring access to important resources. All role activations must go through PIM to maintain an auditable, time-limited access model — preventing unnecessary persistent access to sensitive systems and ensuring access is only granted when needed.

🏠 Home › Privileged Identity Management
Privileged Identity Management

Manage just-in-time privileged access to Azure AD and Azure resources.

2
Navigate to the Groups Section

In the PIM left-hand navigation panel, under Activate, click on Groups — not "Microsoft Entra roles" or "Azure resources". You will land on the My roles | Groups page showing your eligible group memberships.

💡 Why this step?

R&R now uses PIM for Groups rather than direct role activation. A security group in Entra can be linked to multiple roles simultaneously. By activating at the Group level, you activate all BAU roles assigned to that group in one single action — saving time and reducing the need for repeated individual activations.

🏠 Home › Privileged Identity Management | My roles › My roles
My roles | Groups
Eligible assignments
Active assignments
Expired assignments
RoleGroup
Memberv1 Azure platform team
3
Activate Your Group Membership

Click the Activate link next to your eligible group assignment. In the activation dialog that appears:

  • Leave Duration set to 8 hours (the default for BAU)
  • In the Reason field, enter BAU
  • Click the Activate button
💡 Why this step?

A reason is required by PIM to maintain an audit trail explaining why access was requested. Entering "BAU" (Business as Usual) documents that this is a routine activation. The 8-hour time limit enforces the principle of least privilege — access automatically expires so you never hold elevated permissions longer than necessary.

Activate – Member
Privileged Identity Management | Groups
8
4
Complete Multi-Factor Authentication (MFA)

After submitting the activation request, you will be prompted to verify your identity via Multi-Factor Authentication (MFA). Open your phone authenticator app (e.g. Microsoft Authenticator) and approve the sign-in request or enter the one-time passcode shown.

💡 Why this step?

MFA is a critical security control required when activating privileged access. Even if your password were compromised, an attacker cannot activate PIM roles without also having physical access to your phone. This second factor ensures elevated permissions are only granted to the verified, authorised individual — protecting the organisation's entire Azure environment.

⚠ Important

Ensure your phone is accessible and your Authenticator app is configured before starting the activation. The MFA prompt may time out if not approved promptly.

5
Await Approval (If Required for Sensitive Roles)

If your group membership includes sensitive or highly privileged roles, your activation request will be sent for approval. A second person who is a member of the Approvers group must approve your request before access is granted. Wait for their approval before proceeding.

💡 Why this step?

The four-eyes (dual authorisation) principle is a security best practice for high-risk access requests. Requiring a second person to approve sensitive role activations prevents any single individual from unilaterally gaining access to critical systems — significantly reducing the risk of insider threats, accidental misuse, or compromised accounts obtaining dangerous levels of access without oversight.

📝 Note

Not all activations require approval. Standard BAU role group activations are typically self-approved immediately. Only roles specifically designated as sensitive will trigger the approval workflow. You will receive a notification once approved.

6
Verify Your Active Assignments

After approval, navigate to My roles → Microsoft Entra roles → Active assignments tab to confirm your roles are now active. They should appear with a Group membership type and Assigned status.

After this initial activation you may also be eligible for additional more privileged roles that can be found in the Roles tab for a second activation if needed.

💡 Why this step?

Verifying your active assignments confirms the PIM activation completed successfully and your Entra ID roles are live. This is important to check before beginning any work requiring elevated permissions — ensuring you won't be blocked mid-task due to a failed or pending activation.

⚠ Important

Activation sometimes requires another logon to the Azure portal to view resources. If resources are not immediately visible after activation, open a new browser tab and log back in to the Azure portal.

🏠 Home › Privileged Identity Management › My roles
My roles | Microsoft Entra roles
Eligible
Active assignments
Expired
RoleScopeMembershipState
Security ReaderDirectoryGroupAssigned
Global ReaderDirectoryGroupAssigned

🎉 Activating the group activates all BAU roles assigned to it in one go!

🌿 Azure Resources Activation  Optional

You may also be able to activate Azure resources, found under the Azure resources tab in PIM. This only applies if your job role requires you to administer Microsoft Azure directly. After logging in, groups associated with Azure resources will appear as eligible assignments. Resources on the old Landing Zone are available here and will be migrated to use PIM for groups as each workload is migrated during the upcoming Azure Optimisation project.

🎉 All Steps Completed!

You have successfully activated your PIM roles for groups. Your BAU roles are now active for 8 hours.

Remember: if resources are not immediately visible in the Azure portal, open a new tab and log in again.