Privilege should be specific, temporary, and reviewable
Reduce the number of identities that can make high-impact Azure changes at any moment
Azure privilege spans two connected authorization systems. This Azure PIM and RBAC privileged access guide examines Microsoft Entra roles that control users, applications, authentication, Conditional Access, and role administration, plus Azure role-based access control for management and data operations across management groups, subscriptions, resource groups, and resources. A secure design must review both systems, their inheritance, custom roles, classic administrators, service principals, managed identities, and any path that can grant additional access.
Microsoft Entra Privileged Identity Management can make eligible access time-bound, require activation controls, generate notifications, and support access reviews. PIM reduces standing privilege, but it does not correct an overpowered role, excessive scope, weak approver design, or an identity that should not be eligible at all.
Start with authority, not job title. Inventory the exact actions and data a role can reach. “Cloud administrator,” “engineer,” or “vendor” does not explain whether an identity can assign Owner, change a Key Vault, disable logging, delete backups, or alter Conditional Access.