Two years ago, we implemented AzureAD PIM in our baseVISION infrastructure to rise the security level. But after some time, we recognized, that it has too many drawbacks because the activation of the requested role took sometimes longer than a few hours. Especially in Exchange, Skype or Intune this was a big Problem. Therefore, we had to migrate back and assign the roles permanent. Now in January I discovered that Uservoice Feedback of PIM was updated. So, I started playing around with it again it’s now really working.
This led me to a part in PIM which I have never used. It’s PIM for Azure IaaS resources. I will share my feedback about it in this blog.
Enable Azure PIM for a user
Now the PIM functionalities are working without issues for O365 and Azure IaaS. Therefore, we can start really using this solution in our customer environments. It’s a big security benefit.