Information
Provisioning users to privileged roles within a PAM system enables enforcement of numerous privileged access policies and monitoring. If privileged users are assigned directly to roles in the M365 admin center or via PowerShell outside of the context of a PAM system, a significant set of critical security capabilities are bypassed.
Solution
1. Perform the steps below for each highly privileged role. We reference the Global Administrator role as an example.
2. In Microsoft Entra admin center select Roles and administrators.
3. Select the Global administrator role.
4. Under Manage, select Assignments and click the Active assignments tab.
5. For each user or group listed, examine the value in the Start time column. If it contains a value of -, this indicates the respective user/group was assigned to that role outside of Microsoft Entra ID PIM. If the role was assigned outside of Microsoft Entra ID PIM, delete the assignment and recreate it using Microsoft Entra ID PIM.