Articles

[PIM 6] PIM for Azure Resources: JIT Over Azure RBAC

The same discipline over Azure RBAC, with a different administrative surface, a different API, a different set of people who can even see the assignments, and one operational tax: role settings here do not inherit down the scope tree.

[PIM 3.1] Build Sheet: PIM for Groups End to End

Build a role-assignable group carrying three directory roles, bring it under PIM, and make the administrators eligible for membership rather than in it. One activation grants the tier; two of the steps cannot be undone.

[PIM 3] PIM for Groups: Privilege in Bundles

Groups are how just-in-time access scales past a handful of roles, and they carry constraints sharp enough to reshape a design: a hard cap of 500, a documented slow path through Exchange and SharePoint, and a door that only opens one way.