Eligible, Not Active: Why PIM-Enabled Groups Are the Right Way to Hold a Role
PIM-enabled groups should make users eligible, not permanently active. Activation should be time-limited, logged, and monitored for direct additions that bypass PIM.
PIM-enabled groups should make users eligible, not permanently active. Activation should be time-limited, logged, and monitored for direct additions that bypass PIM.
Privileged Access Groups work in layers: security groups hold permissions, PIM makes membership eligible, activation grants time-bound access, and some directory roles require a second activation.