PLEASE NOTE: Since the creation of this training, Microsoft has renamed Azure Active Directory to Microsoft Entra ID. While the functionality is the same, the exam will only reference Microsoft Entra ID.
Overview
Join Knox Hutchinson as he discusses Azure's Active Directory Privileged Identity Management, the PIM approval process, just-in-time, and time-bound access.
Learn how to manage, control, and monitor access to your organization's resources.
Privileged Identities
The run-as-admin of Azure security, Privileged Identities lets us monitor and approve when someone needs administrative rights.
Knowledge Check
In PIM, an eligible privilege is not active by default. True or false?
Enabling PIM
To enable PIM, special licensing and consent are required. In this Nugget, we'll walk through how to enable PIM.
Knowledge Check
PIM requires an Azure Active Directory Premium P1 or EMS E5 license. True or false?
Enabling Just-In-Time Access and Privileges
To enable PIM, you should start with the just-in-time access elevation. In this Nugget, we'll walk through configuration and activation of an eligible role.
Knowledge Check
Activating with MFA requires a sign-out and sign-in. True or false?
Enabling Time-Bound Access
Rather than going through an activation process, we can go through an assignment process with time constraints. We'll configure these constraints in this Nugget.
Knowledge Check
To make a time-bound assignment active, the assignment type must be which of the following?
Enabling PIM Approval Process
The most powerful auditing and control mechanism in PIM, the approval workflow process, is easy to configure. In this Nugget, we'll walk through the steps.
Knowledge Check
The delegated approval user must have a Premium P2 or EMS E5 assigned to their individual account. True or false?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Privileged Identities
0:00Introducing privilege identities.
0:03So giving everyone admin level access
0:06is obviously not the right thing to do.
0:07That's obviously a security risk,
0:09but the flip side of that is sometimes
0:12are end users legitimately need the admin level access in order
0:17to perform the tasks to do their job.
0:18I mean, take a look at this guy right here.
0:20He is developing some code on his website,
0:22he's ready to deploy it to test, and it turns out
0:25that the DevOps engineer never actually made
0:28the correct deployment slots before they quit their job.
0:30Well, now this guy needs to stand up a deployment slot
0:33so that he can deploy as code and test it out,
0:36but he doesn't have the access to do it.
0:38So, yeah, we could use something like RBAC, role-based access
0:41controls, or we could grant this guy owner level
0:44privileges to the resource group or the resource itself,
0:46then he could deploy whatever he'd want and run up whatever
0:49bill he wants, or we could look in
0:51to some more powerful identity management tools.
0:55What privilege identity management in Azure
0:57is all about is the concept of least privilege
0:59but ratchet it up a notch.
1:02And I am just so excited that I get to talk to you about PIM.
1:05I just want to pull up the Azure portal right now, dive in
1:07and start showing you how it works, and just say,
1:09you can figure it out as you go along,
1:11but we got to slow down because this is kind of a big topic
1:14and we need to set up some key terms and some key processes
1:17upfront.
1:18At the heart of PIM is the concept
1:20of permanent privilege versus eligible privilege.
1:24Now permanent privileges is exactly what it sounds like.
1:27It's exactly what we did when we were
1:29doing RBAC, when we talked about role-based access controls.
1:32When you grant someone the global administrator right
1:35and do nothing else, they are the global administrator.
1:38Their role is now permanently global administrator
1:41and they can permanently do whatever they want.
1:44But if we use something like PIM, permanent doesn't go away,
1:48but now we can say that this particular user, like this code
1:51developer right here, is now eligible for an owner role.
1:56And if they want to use those owner level privileges,
2:00they have to go through an elevation task or elevation
2:03workflow in order to be approved in order to get those access
2:08rights.
2:09So that approval access looks something like this.
2:11So let's say he is ready to deploy his code,
2:13but he can't deploy his code because he
2:14needs to actually spin up a deployment slot first,
2:17and that does require at least contributor level access,
2:20but owner level access could work as well.
2:22So what this guy is going to do is he's going to log into Azure
2:25and go to the PIM portal where he's
2:27going to request elevated rights for the role
2:31that he is eligible for.
2:33He simply clicks an Elevate button
2:35that kicks off the workflow in order to start him
2:38in elevating his tasks.
2:40Now if we have granted him the ability to do that,
2:43if he is actually truly eligible to do it,
2:45then he can go through several different kinds of steps
2:48in order to actually get elevated.
2:49The first option, we could simply
2:51force him to use multi-factor authentication,
2:53because if he's got his cell phone,
2:55then we know that he is who he is because he not only knows
2:58something, but he also has something in order to verify
3:01his identity.
3:02The other thing that we can do is
3:04we can enable something called time-bound access,
3:07and this is saying that he is only
3:08allowed to elevate his privileges
3:10during a specific time set.
3:13For instance, if we know he's going
3:14to be working on deploying this code,
3:16and he may need some special privileges,
3:18we can allow him to elevate is permission for the next 48
3:22hours, let's say.
3:24And then beyond that, we can say during that 48 hours,
3:27he's only allowed to elevate his privileges
3:29for one hour at a time.
3:31Now he can't go through renewal process,
3:34but he has to give reasoning, documented reasoning, as to why
3:37he's asking to extend his elevated privileges.
3:41And the actual last option that we could actually setup
3:44is we could set up an approval workflow process,
3:47so that if this particular user requests to elevate
3:50his privileges, this workflow process would actually fire off
3:53an email to an approving manager or any other person
3:56that we delegate permission to to approve
3:59this particular developers access.
4:01And once it's been approved, this particular user
4:03will get notified you've been approved,
4:05and you have this much time to do your work.
4:08So do you see how this is way more powerful than something
4:11like role-based access controls?
4:13In this particular instance, we'll
4:14actually be able to keep running tabs on who is doing what
4:18and when because we're granting privileges to people
4:21if they have to go through an elevation process
4:24in order to actually get the rights that they
4:26are requesting.
4:27This is the concept of just in time access.
4:31They get the access that they need just
4:34in time to perform the action they need to do,
4:37and they only have access for the length of time
4:39that we delegate or designate.
4:41And the best case example of this is a global admin.
4:44The global admin rarely actually needs global admin rights.
4:48They don't do global admin tasks day in and day out.
4:51So they should only have to elevate into global admin
4:54when they truly need to do it.
4:56And by setting up PIM in this particular instance
4:59and not having permanently assigned to all these roles,
5:02we are reducing our attack footprint tremendously.
5:05Now some key prereqs that go into PIM.
5:08First of all, you have to have an Azure AD Premium P2
5:11license or an EMS, that's Enterprise Mobility
5:15and Security Suite, E5 license.
5:18And once those are enabled, the global admin who is actually
5:20going to be enabling PIM within the environment,
5:23they also have to have multi-factor authentication
5:25already set up.
5:26But once you've got those, you're good to go.
5:28You're ready to start rocking and rolling with PIM.
5:30So we've introduced privileged identities,
5:32this amazing technology where we can really lock down
5:35who is doing what and when.
5:37Over the next few Nuggets, we're going
5:38to be enabling PIM in our environment,
5:40then setting up things like just in time
5:42access, the time-bound access, and the approval workflow.
5:45We'll see you there.
5:46I hope this has been informative for you,
5:48and I'd like to thank you for viewing.
Enabling PIM
0:00Enabling Privilege Identity Management--
0:02Yeah, PIM sounds pretty great, right?
0:04I mean, the idea here is that you only
0:06get the administrative access when you
0:09need the administrative access.
0:10And there's a system of checks and balances
0:12here, so that people can only get administrative access when
0:15they've gone through a sort of workflow or approval process.
0:19And this is a huge benefit to us,
0:20because it's going to cut down on careless accidents happening
0:23because people are over provisioned with access.
0:25And it's also going to reduce our attack footprint
0:27because as soon as an account gets compromised,
0:29the hacker doesn't have administrative access
0:32by default.
0:33So we're convinced.
0:34This is what we want.
0:35It's time to jump in the portal and get started going.
0:38You can get to PIM by doing Create a Resource
0:40and just searching for it.
0:42Or you can see right here, I've got Azure AD Privilege Identity
0:46Management already pinned.
0:47Going to All Services and searching
0:49for Privilege Identity Management
0:50will also bring that up.
0:51So what we need to do to enable PIM is first of all,
0:54you have to have an Azure Active Directory P2
0:57license, or an EMSE5 license.
1:00That's Enterprise Mobility and Security Suite.
1:03So I already have an Azure AD P2 license,
1:05so I'm going to click on the Azure AD Privilege Identity
1:07Management here.
1:08And what we have to do is we have
1:10to consent to enabling Privilege Identity Management.
1:13You can see right below the Quick Start button,
1:15there's this Consent to PIM.
1:17And once it loads up it says, hey, the status
1:19has checked out OK, click the Consent button to get going.
1:22We'll click Consent.
1:24And it's going to say, are you sure?
1:25Yep, I'm definitely sure.
1:26We'll click Yes, and that's it.
1:28That's all there is to getting PIM up and running.
1:30Let's just poke around.
1:31See what we've got here.
1:32Well, first up we've got My Roles.
1:34And the very first time you actually click into My Roles,
1:37you have to sign PIM up into Azure AD
1:40so that it can scan through Azure AD
1:42and make sure that it can successfully
1:44read all of your roles and current users
1:46that you already have.
1:47Just clicking the little sign up button here will do that.
1:49And you see it says, sign ups have completed successfully.
1:51Feel free to close this window.
1:53So we'll do just that.
1:54We'll click out, and click back into it.
1:56And now we are actually in the Azure AD roles.
1:58This particular screen that we're looking at here
2:00is the eligible roles.
2:02If I were eligible for any roles right here,
2:05this is where I could go to activate those roles,
2:08or see the current status of that, maybe
2:10how much time is left.
2:11Now if I want to see the roles that I already
2:13have elevated and activated, I can click on Active Roles.
2:16And you can see because I am the domain owner here,
2:19I by default have three permanently assigned roles.
2:23So we got the Global Administrator here
2:25that is permanently assigned.
2:27And just a quick overview of the other items
2:29in the Setting page.
2:29I'll click back on Privilege Identity Management here.
2:32We can see my request.
2:33These are the requests that I have opened.
2:35What is the status of the elevation requests that haven't
2:38been sufficiently met yet?
2:40Maybe we're waiting on an email approval process,
2:42and our boss just hasn't gotten around to clicking Accept yet.
2:44We can go poke him and make sure they've got that going.
2:46We'll go back to Privilege Identity Management.
2:48We also have the ability to approve requests,
2:50if we have been delegated the permissions to do that.
2:53Similarly, back on Privilege Identity Management,
2:55we can also review access for Active Directory roles
2:58that we've set up to keep monitoring and reviewing access
3:01on too.
3:01So that's it.
3:02Setting up and enabling Privilege Identity Management,
3:04there's nothing to it.
3:05But in the next few Nuggets, we're
3:06going to be actually talking about how to configure just
3:09in time access, time down access, and the workflow
3:11approval process.
3:12I hope this has been informative for you,
3:14and I'd like to thank you for viewing.
Enabling Just-In-Time Access and Privileges
0:00Configuring Just-In-Time Access.
0:03So in the last Nugget, we got pim up
0:05and running in our environment, but we
0:06didn't can figure anything yet and we
0:08need to get jumping on that right away because I
0:11want to lock down my global admins account.
0:13Check this out.
0:14If I go to Azure AD roles real quick, and then I simply
0:17click on Roles here in the left-hand side,
0:19you'll notice the pane did change when
0:21I clicked on Azure AD Roles.
0:22I'll click on Roles, and we'll scroll on down
0:24to Global Admins, and we'll see currently Simon Simoneaux is
0:29a permanent global admin user.
0:31Well, I don't want him to be permanent.
0:32You see, I'm the only one I want to be permanent because I'm
0:34the owner of the company.
0:36And I don't want Simon to be permanent by default
0:38because he may click on something
0:39or do something by accident.
0:40I want him to go through an elevation process.
0:43So to go about configuring that and the ways
0:45that we can actually set up the configuration process,
0:48we need to get started like this.
0:49Let's go back to Privilege Identity Management.
0:51We'll choose Azure AD Roles.
0:53Them we'll choose Settings.
0:55Then right here, we've got these settings
0:56that we can start configuring-- roles, alerts,
0:59and access reviews.
1:00Well, we're configuring these settings for a role.
1:02So I'll click on Roles, and it'll
1:04bring up the list of roles that we can start
1:05configuring the settings for.
1:07Let's click on Global Administrator,
1:08and the first thing we want to draw your attention to
1:10is the slider at the top.
1:12What is the maximum hours that this role can be activated for?
1:16One seems a little tight so I may change that to two,
1:19make that a little bit easier.
1:20I do want to be notified when another global admin has
1:24been activated.
1:25So I'll go ahead and enable notifications
1:26here so that way we get a notification
1:28email when someone has gone through the elevation process.
1:31Now, I don't need a ticket request or any sort of item
1:34like that, but you can force someone
1:36to actually enter in information like a ticketing system
1:39when they're going through the request process.
1:41Now, global admins, by default, multi-factor authentication
1:45is enabled and you can't change it.
1:47So when someone goes to activate this role,
1:49it is going to bring up a GUI for them
1:51to actually go through a multi-factor authentication
1:53approval process.
1:55And the last one is the require approval.
1:57This is where another user is going
1:59to be delegated permissions, and we
2:00require them to approve the elevation request.
2:03They'll get an email.
2:04They just click on the link, choose Approve.
2:06Then the end user who's doing the requesting,
2:08they'll get an email letting them
2:09know that it was approved or denied.
2:11So I like these settings that we've got here.
2:12We've changed the hours that it can be activated.
2:14We've changed the notifications on activation.
2:16We'll click Save, and updated settings successfully.
2:19That's that easy Let's go back to Azure AD roles,
2:22and this time we'll just click on Roles.
2:25Now scroll on down to Global Administrator,
2:28and we'll see Simon Simoneaux here.
2:29We can see he's still got the permanent access.
2:31If I click the little dot dot dot right here,
2:33we can change it to make eligible.
2:35And now Simon Simoneaux is not a permanent global admin.
2:38He will have to go through a multi-factor authentication
2:41approval process after he's gone through
2:44and elevated his status.
2:45Let's check that out.
2:46I've logged out of the portal and logged back in as Simon
2:49here.
2:49Let's just find our way over to Privilege Identity Management.
2:52We'll give it a click, and now we
2:54should be able to go into Roles and see what
2:56we're eligible for activation.
2:58Check it out.
2:58My global administrator is currently not active.
3:01We don't have any pending requests.
3:02And I want to activate it.
3:04We know this is going to be activated for two hours.
3:06I'll click Activate, and we'll click Activate again,
3:09and it says what is the duration that we
3:11want to activate this for.
3:12I'm just going to go ahead and scale it
3:14all the way back to just a half an hour,
3:16and my activation reason is demonstration.
3:18How about that?
3:19We'll click Activate, and it goes through the three stages
3:22of activation here.
3:22Stage 1, Processing Your Requests
3:24and Activating Your Role.
3:26And after about 30 seconds, all three stages
3:28have been successful.
3:29But check it out.
3:30Now we have to sign out and sign back in in order for this
3:34to take effect.
3:34Guess what?
3:35Because that's the multi-factor authentication part.
3:37So we'll sign out.
3:38We'll sign back in.
3:39Type in our password.
3:41It's going to prompt me for multi-factor authentication.
3:44And now I'm signed back in.
3:46Let's just check this out.
3:47Let's go back to Privilege Identity Management real quick.
3:50We'll search for Privilege Identity Management, My Roles.
3:54And now you can see, under my eligibility roles
3:56we actually have valid access here.
3:58If we go to Active Roles, you can see it also
3:59shows up as active here.
4:01And when I'm done, I can simply click Deactivate.
4:03Let's just go ahead and do that just for good measure.
4:05We'll go ahead and click Deactivate again and click Yes.
4:08And after a few seconds, that's it.
4:10That's all there is to it.
4:11We have now enabled just-in-time access
4:13and walked through a demonstration on how
4:14our end users can use it.
4:16I hope this has been informative for you,
4:17and I'd like to thank you for viewing.
Enabling Time-Bound Access
0:00Configuring Time-Bound Access.
0:02So one of the big distinctions between Just-in-Time access
0:06and Time-Bound access is that Just-in-Time access requires
0:09the end user to go through an activation and elevation
0:12process.
0:13Whereas the Time-Bound access, we're
0:15just assigning the role or privilege to the end user
0:19without them having to go through an activation process.
0:21They're going to have the rights they
0:23need, not only for a designated amount of time to do it.
0:26This is perfect for maintenance windows.
0:28This is perfect for standing up new environments.
0:30And you know that someone's going
0:31to need access for a designated amount of time.
0:34In this particular instance, let's pretend Simon Simoneaux,
0:36the guy that we've been picking on throughout this module,
0:39needs access to the Owner permission of our subscription
0:44for 15 days.
0:45What I'm going to do from the PEM portal to get
0:47started with that I'm going to click on Azure resources.
0:49Now what it brings up on the screen is that we can manage
0:52the pay-as-you-go subscription right here.
0:54Let's go and give that a click.
0:56And something that's just worth pointing out,
0:57it brings you into a really cool little dashboard
1:00for all of the active role assignments,
1:01distribution, and changes over time
1:04that are going on within the specified subscription.
1:06So this is a really great dashboard for auditing
1:08and seeing what's really going on here.
1:10Now to get started configuring this,
1:12I'm going to click on Role settings here.
1:13And these are all of the role settings
1:16that are allowed within that subscription.
1:18Let's just search for Owner real quick.
1:20And we can see here is Owner.
1:22We'll give Owner a click.
1:23And this is where we can actually
1:24go about setting up the role settings for the Owner
1:28privilege.
1:28Now the first thing to notice is we've
1:30got the distinction between Assignment and Activation.
1:33Well, Activation t is talking about the settings hat are
1:35revolving around Just-in-Time access, whereas the Assignment
1:39here is going to be dealing with the Time-Bound access
1:41that we're dealing with.
1:42Now the first two settings here are
1:44Allow permanent assignments.
1:45Check that out.
1:46And if we had an assignment that didn't expire?
1:48Well, guess what, that's just a work
1:50around to get permanent assignment.
1:52Now there is the distinction between a permanent eligible
1:54assignment and a permanent active assignment.
1:56This is saying we can have someone
1:58be permanently eligible.
2:00Or we can have someone be permanently active.
2:02Well, those are all well and good.
2:03But the real Time-Bound access happens right here
2:06in the bottom chunk.
2:07This is saying expire active assignments after so much time,
2:11require multi-factor authentication,
2:13and require justification on an active assignment.
2:16So when I go to assign someone, being the administrator,
2:19I have to justify why I'm assigning someone
2:22with those permissions.
2:23One month seems a little too high for me.
2:26So I'm going to on the Edit button here.
2:27And let's change this to 15 days.
2:31We'll also require multi-factor authentication
2:33on an active assignment.
2:34And if we wanted to go ahead and make sure
2:36that we could enable permanent assignments,
2:38we could do that right here as well.
2:39But I like these settings the way they are.
2:41I'll click Update.
2:42And we now have the Owner role that
2:44has been edited and updated.
2:45So let's go back to the roles where we can see
2:48and manage the existing roles that we have.
2:50Let's click on Owner.
2:52And let's add a member here.
2:54We're going to choose our member of Simon Simoneaux.
2:57We'll just search for his name.
2:59Give him a click.
3:00Choose select.
3:01You can see his default Assignment type is eligible.
3:04And this will actually specify when the eligibility starts
3:07and when the eligibility finishes.
3:09But to actually make this a Time-Bound access,
3:11let's go and changes to be Active.
3:13And now we have to enter that justification.
3:15We'll just call this Time bound demo.
3:18And you can see we've got the 15-day period set
3:20up here with the time and date that it starts.
3:22We'll click OK.
3:23And we'll click Add.
3:24And we've now configured Time-Bound access
3:26for our user Simon Simoneaux.
3:27I hope this has been informative for you.
3:29And I'd like to thank you for viewing.
Enabling PIM Approval Process
0:00Configuring PIM eligibility approval workflows--
0:03that is a mouthful.
0:04But basically what we're saying is when somebody requests to be
0:07elevated into their administrative privileges,
0:10we want to have an approval process happen
0:12where somebody else that we've delegated permissions to
0:15can approve that person's request to be elevated.
0:18Now, in the past couple Nuggets, we did just-in-time access.
0:20We were talking about Azure Active Directory roles.
0:23And then we did time-out access, and we
0:24talked about Azure Resource roles like owner, contributor,
0:28and so on.
0:28Because eligibility workflows are really easy to configure,
0:32I want to show you how to do both of these
0:34within the same Nugget.
0:35But first up, the very first step
0:37is choosing who you're going to be
0:39delegating this permission to.
0:40In my particular case, I want to be
0:42the one who's approving whenever my people get elevated.
0:44So I'm going to go to Azure Active Directory first.
0:47I'm going to choose my account under Users.
0:50I'll go ahead and give myself a click,
0:51and we're going to assign myself an Azure P2 license.
0:55Now, you can also do this with an EMS E5 license, as well.
0:58We'll go ahead and click Assign.
1:00We'll choose Products.
1:01We'll choose the Azure P2 license, Select,
1:04and choose Assign.
1:05There we go.
1:05The license was assigned that quickly.
1:07All right.
1:07Now we're ready to get back into the PIM portal
1:09and start configuring the approval workflow process.
1:12Let's start with Azure AD roles.
1:14In this particular case, once we click on Azure AD Roles,
1:16I'm going to click on Settings.
1:18And let's say when we go into Roles here,
1:20we want to configure the global administrator to go
1:22through an approval process.
1:24If we scroll down to Global Administrator,
1:26we'll give it a click, and the very last option,
1:28if you remember, was Require Approval.
1:30We'll click Enable here.
1:31And the selected approver is the last part
1:33that we have to configure.
1:34We'll click on this little section here,
1:36and we'll choose my account and click Select.
1:39OK.
1:39That's it.
1:40Once we've got this done, we'll click Save.
1:42And now whenever somebody goes to the eligibility process
1:44of elevating into the global admin role,
1:47my account will receive an email where
1:49I can click on a link to approve or deny their request.
1:52Now, that's it for the Azure AD.
1:54Let's jump back into the PIM portal
1:56and configure this for Azure Resources.
1:58So from the PIM portal, we'll click on Azure Resources
2:01this time.
2:02We'll click on the subscription.
2:04Now we'll click on Role Settings here.
2:07And let's say we want owner to go
2:08through this sort of process.
2:09Now, we talked about assignment recently.
2:11That was for time-bound access.
2:13But now we're talking about the activation process.
2:16So if we're assigning someone to be eligible instead of active,
2:19this is going to go through the approval workflow process.
2:21And the two items that we're interested in--
2:23the very last two, require approval
2:26and who is the approver.
2:27Let's click on Edit.
2:28We'll scroll on down and say, check off
2:30the box that requires the approval to activate,
2:32and we'll go ahead and just search for my account again.
2:34Give it a click, Select, Update.
2:38That's it.
2:38That's all there is to configuring the approval
2:41workflow process.
2:42Now whenever somebody goes to elevate their account,
2:44we're going to receive an email that allows us to approve
2:47or deny their request.
2:48I hope this has been informative for you,
2:50and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year