EASYENTRA Blog

News & Updates

PIM Group Assignments in Microsoft Entra: Membership Eligibility vs. Role Eligibility

How to Configure Privileged Identity Management for Groups in Microsoft Entra

Microsoft Entra Privileged Identity Management (PIM) offers multiple ways to provide just-in-time (JIT) administrative access. When using groups together with Microsoft Entra roles, administrators often encounter two seemingly similar approaches:

  1. Assigning users as permanent members of a group eligible for Microsoft Entra roles
  2. Assigning users as eligible members of a group with permanent Microsoft Entra roles

Although both methods eventually allow users to activate privileged access, they operate differently and are intended for different scenarios. Choosing the appropriate model helps reduce activation delays, simplifies administration, and ensures compatibility with management tools.

Let’s look at how each model works and when you should use them.

Two Ways to Configure PIM for Groups in Microsoft Entra ID

Microsoft supports two ways to provide privileged access through role-assignable groups. Although the end result is the same, the activation target is different. Understanding the difference is important because it affects both the user experience and compatibility with EasyEntra.

Method 1. Active Group Membership + Eligible Role Assignment

In this model,

  • Users are permanent members of a role-assignable security group.
  • The group itself is assigned to the Microsoft Entra role as an eligible assignment.
  • When users activate PIM, they activate the directory role, not their membership in the group.

Here, the group membership never changes. Only the role assignment is activated.

How to Configure Eligible Role Assignment in Microsoft Entra PIM

Follow these steps to configure a role-assignable group with an eligible Microsoft Entra role assignment in Microsoft Entra PIM.

Step 1: Create a Role-Assignable Group

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Identity > Groups > All groups and click New group.
  3. Set Group type to Security and enter a group name.
  4. Toggle Microsoft Entra roles can be assigned to the group to Yes.
  5. Click Create.

Step 2: Add Permanent Members

  1. Open your newly created group and select Members from the left menu.
  2. Click Add members.
  3. Add the administrators who will use this role and click Select.

Step 3: Assign the Role as Eligible

  1. Navigate to Identity Governance > Privileged Identity Management > Microsoft Entra roles.
  2. Click Roles under the Manage menu.
  3. Search for your target role (e.g., Exchange Administrator) and click on it.
  4. Click Add assignments from the top bar.
  5. Under Select member(s), select your role-assignable group and click Next.
  6. Set the Assignment type to Eligible and click Assign.

Step 4: Configure the Activation Policy

  1. Inside the specific role view, click Role settings from the top menu.
  2. Click Edit to configure activation rules (e.g., require MFA, Justification, or Approvers).
  3. Click Update to save.

How to Activate Eligible Group Roles via EasyEntra

Once you’ve configured the role-assignable group with an eligible Microsoft Entra role assignment, users can activate their eligible Microsoft Entra roles directly from EasyEntra. Follow these steps:

  1. Open the EasyEntra tool, expand the Connection Manager tab, and select Entra ID.
  2. Right-click on the tenant connection you are working on and select Activate PIM Roles.
  3. Check the boxes for all the desired roles you need to use. Set your target activation duration, type in a business justification, and add an incident ticket number if required.
  4. Click Activate. EasyEntra will bundle your selections and trigger them all in parallel.
  5. Once the process wraps up, click Reload to quickly verify that your active status is live across all assignments.

Important: This is the recommended configuration for most organizations as role activation across services like Exchange Online and OneDrive is faster. Also, this is the model that EasyEntra's Activate PIM Roles feature is designed to work with. ✅

Method 2. Eligible Group Membership with Active Role Assignment

In this model,

  • The group permanently holds the Microsoft Entra role.
  • Users are eligible members of the group.
  • When users activate PIM, they temporarily become members of that group.

Here, the role assignment never changes. Instead, the user’s membership in the group changes.

How to Configure Eligible Group Membership in Microsoft Entra PIM

Follow these steps to configure a permanently assigned Microsoft Entra role while allowing users to activate eligible group membership through PIM.

Step 1: Create a Role-Assignable Group

  1. Go to Identity > Groups > All groups and click New group.
  2. Set Group type to Security and enter a group name.
  3. Toggle Microsoft Entra roles can be assigned to the group to Yes.
  4. Click Create.

Step 2: Assign the Role Permanently to the Group

  1. Navigate to Identity > Roles & admins > Roles & admins.
  2. Search for your target role (e.g., SharePoint Administrator) and click on it.
  3. Click Add assignments.
  4. Under Select member(s), select your newly created group and click Next.
  5. Set the Assignment type to Active and click Assign.

Step 3: Assign Users as Eligible Members

  1. On the PIM Groups dashboard, click on your group name.
  2. Select Assignments from the left menu and click Add assignments.
  3. Choose Member in the role dropdown.
  4. Under Select member(s), choose your target users and click Next.
  5. Set the Assignment type to Eligible and click Assign.

Step 4: Configure the Group Activation Policy

  1. Inside your PIM Group menu, click Settings under the Manage section.
  2. Click on the Member role string.
  3. Click Edit to set up membership rules (e.g., require MFA, Justification, or Approvers).
  4. Click Update to save.

Important: EasyEntra does not support activation of eligible group memberships with active role assignments. Since users activate group membership rather than the Microsoft Entra role itself, these assignments won't appear on the Activate PIM Roles page. ❌

Key Differences Between the Two Models

The following comparison highlights how these two PIM models differ in configuration, activation, and day-to-day administration.

FeatureMethod 1Method 2
1. Group membershipPermanentTemporary during activation
2. Role assignmentEligibleActive
3. What PIM activatesMicrosoft Entra roleGroup membership
4. User becomes group member during activationNoYes
5. Microsoft Entra role becomes active during activationYesNo (already active on the group)
6. Activate PIM Roles via EasyEntraSupported Not supported

Microsoft recommends the same model EasyEntra uses when assigning PIM access to Exchange or SharePoint. Activating groups (instead of roles) may carry considerable delays before access is actually granted in these services: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/concept-pim-for-groups#make-a-group-of-users-eligible-for-a-microsoft-entra-role

Free 30-minute demo

try 30 days for free

GET EASYENTRA NEWS

Opt out at any time

“One of the best products I've used.”
Gary Shurland
Chief Information Officer, Mirick, United States
“This tool has been invaluable in streamlining our IT processes.”
Tyson Mckay
Chief Information Officer, Southwest Network, United States
“This product has been a miracle for our Help Desk. EasyEntra has completely transformed how we handle Microsoft 365 administration.”
Doug Sanders
Manager of Technical Customer Support, Junior Achievement USA, United States
“Your product is such a time saver. I love it!”
Scott Fehr
IT Infrastructure, MEC Aerial Work Platforms, United States
“It's a good product and saves us lots of time for these ongoing quick admin tasks.” 
Chris McFerran
Managing Director, CTech IT Solutions Ltd, United Kingdom
“EasyEntra has significantly streamlined our workflow, simplifying everything. It feels almost like a revolution.”
Johan Sadelius
IT-chef, Arjeplog Kommun, Sweden
I greatly appreciate your assistance and willingness to enhance the already outstanding product.”
Michael I. Wilson
Executive Director of Information Technology, Archdiocese Of Washington, United States
“It's great not having to switch back and forth between the O365 admin center and the Teams admin center to assign groups. I am sold!”
Thomas Madden
Director Information Technology, AutoPayPlus, United States
“I would highly recommend organizations use the solution as it greatly simplifies various tasks.”
S. Roger Singh
Chief Technology Officer, Prasad & Company LLP, Canada
“EasyEntra is time-saving. Love the copy/paste for user/computer groups and the copy to new user.”
Damian Nita
Associate Network Administrator, Shenandoah Valley Westminster-Canterbury, United States
“EasyEntra has transformed our daily IT operations by simplifying user management, reducing errors, and enhancing overall efficiency.”
Henrik Nefling
IT- and Digitalization Manager, Animal Protection Denmark, Denmark