What is Privileged Identity Management?
Privileged identity management (PIM) is the practice of governing who may hold an administrative role and for how long. Instead of granting a person permanent Global Administrator or Exchange Administrator rights, PIM marks the person as eligible for the role. When they need it, they activate it for a defined window, usually with multi-factor authentication and, for the most sensitive roles, a second person's approval. When the window closes the role is removed automatically, and every activation is written to an audit log.
The best-known implementation is Microsoft Entra ID Privileged Identity Management, which is included with Entra ID P2 licensing. An administrator defines which roles are eligible, who can hold them, the maximum activation length, whether a justification must be typed, and whether approval is required. PIM also runs scheduled access reviews, prompting an owner to confirm that each eligible assignment is still needed. The result is that on a normal day the tenant may have zero active global administrators, and an attacker who steals a technician's password gains an ordinary user account rather than the keys to the company.
For a small or mid-sized business the practical benefit is that admin rights stop accumulating. Over the years, staff and former IT providers collect permanent roles that nobody remembers to remove. PIM turns those into eligible assignments that expire and get reviewed, which is exactly the evidence an auditor or insurer wants when they ask how administrative access is controlled.
NetSys configures Entra ID PIM as part of every managed agreement, alongside its privileged access management controls. Engineers convert standing admin assignments to eligible roles, set activation limits and approval rules, enable notifications when a role is activated, and schedule the access reviews so the tenant is re-checked on a fixed cadence. The privileged identity management service page describes the setup in more detail.
Why it matters for a small business
If your Microsoft 365 tenant has five people with permanent Global Administrator rights, each of those five logins can take down the whole company, and a phished password on any one of them is a full compromise. PIM lets those people keep doing their jobs while holding admin power only for the hour they need it, with a log that shows who activated what. Insurers and compliance frameworks increasingly ask for exactly this. It is a configuration change rather than a new product if your licensing already includes Entra ID P2.
Privileged Identity Management (PIM): FAQs
Is PIM included in Microsoft 365?
Entra ID Privileged Identity Management requires Microsoft Entra ID P2, which is included with Microsoft 365 E5 and available as an add-on for other plans, including Business Premium. Business Premium itself includes Entra ID P1, which covers Conditional Access but not PIM. Microsoft's licensing requires the P2 license for the people who hold eligible roles, approve activations or perform access reviews, rather than for every user in the company, so a small business usually licenses only its administrators.
Do we need PAM if we already have PIM in Entra ID?
Usually yes, because PIM covers who can activate a role in Entra ID but does not protect the credentials of accounts outside it: firewall admins, backup consoles, local administrator passwords, service accounts and vendor logins. PAM vaults and rotates those credentials and records privileged sessions. Think of PIM as the answer to whether someone should be an admin right now, and PAM as the answer to how that access is protected while it is in use. NetSys treats them as one sequence and includes both in a managed agreement.
How does just-in-time admin access work?
A user who is eligible for a role opens the PIM portal, requests the role, gives a reason and completes MFA. If the role requires approval, a designated approver gets a notification and grants or denies the request. The role becomes active for a set period, often between one and eight hours, and then disappears without anyone having to remember to remove it. The activation, the reason and the approver are all logged, which is what makes the model auditable.
More terms
Prompt Injection
Prompt injection is an attack that hides instructions in content an AI system reads, such as an email, to make it break its rules or take harmful actions.
Privileged Access Management (PAM)
Privileged access management (PAM) is the set of controls that restrict, monitor and record use of accounts with administrative rights over systems.
Ransomware
Ransomware is malicious software that encrypts a victim's files or systems and demands a payment, usually in cryptocurrency, to restore access to them.
Principle of Least Privilege
The principle of least privilege is a security rule that gives every user, device and program only the access its job needs, and only for as long as needed.
Get the controls, not just the definition.
A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.
