Score:1

Set default settings for all roles in Azure PIM

sr flag

We've just started the process of making roles eligible for assignment in Azure PIM. We have a large collection of resources, each with roles that we want to individually make a user eligible to activate. However, we want to require approval for all of these roles.

By default, there are several settings that PIM automatically puts on roles (such as not requiring approval for resource roles). Obviously, we could go through and change the settings for each role, but that is a reasonably time intensive and error prone process. Is there a way to overwrite these default settings, and require all roles to need approval to activate (for example)?

SamErde avatar
gg flag
Just to be 100% clear, I think you mean "Azure Active Directory PIM," right? The short answer is "PowerShell" and writing that might be something you can find on either GitHub or https://pnp.github.io/#tools.
RetractedRedacted avatar
sr flag
Yes, that is what I meant. I've had a look at Powershell (and also contact Azure support), and it just doesn't look like it's possible. Obviously you could make a script to update/create new assignments and set the settings, but was ideally looking for something through the UI. Resource scopes ended up being the solution for us in the end.
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.