EIDPIM-011: PIM Eligible Role Activation History
- Platform
- Entra ID / M365
- Category
- Entra ID Privileged Identity Management
- Severity
- Info
- Zero Trust pillar
- Identity (weight 1)
- Golden fixtures
- 2
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
Reviewing PIM activation history provides insight into how frequently privileged roles are activated, by whom, with what justification, and for what duration. This audit trail is critical for detecting anomalous privileged access patterns such as activations outside business hours, activations without valid justification, or excessive activation frequency that may indicate a compromised account or insider threat
Recommended value
PIM activation logs reviewed regularly. All activations have valid business justification documented
Remediation
Review PIM activation history via Entra ID > Roles and administrators > Audit logs filtered for PIM operations. Investigate any activations with unusual patterns including off-hours activations, activations by unfamiliar accounts, or activations with vague justifications. Establish a regular review cadence for PIM audit logs as part of security operations
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| no-data | Not Assessed |
Framework mappings
- NIST SP 800-53
- AU-3, AU-6
- MITRE ATT&CK
- T1078.004