Category Governance

Identity and data governance: privileged access, reviews, entitlement, lifecycle.

[PIM 6] PIM for Azure Resources: JIT Over Azure RBAC

The same discipline over Azure RBAC, with a different administrative surface, a different API, a different set of people who can even see the assignments, and one operational tax: role settings here do not inherit down the scope tree.

[PIM 3.1] Build Sheet: PIM for Groups End to End

Build a role-assignable group carrying three directory roles, bring it under PIM, and make the administrators eligible for membership rather than in it. One activation grants the tier; two of the steps cannot be undone.