SC‑300 Study Portal Path 5

Unit 5: Exercise – Assign Microsoft Entra roles in Privileged Identity Management

In this unit, you learn how to assign Microsoft Entra administrative roles using Privileged Identity Management (PIM). Instead of granting permanent access, PIM allows administrators to assign roles as eligible, requiring users to activate them only when needed.

This approach significantly reduces standing privilege and improves security.

Why role assignment in PIM matters

By default, Microsoft Entra ID allows permanent role assignments, meaning:

PIM changes this model by introducing:

Part 1: Assign a Microsoft Entra role (Eligible assignment)

Objective

Make a user eligible for the Compliance Administrator role instead of permanently assigning it.

Step 1: Open Privileged Identity Management

Step 2: Navigate to Microsoft Entra role assignments

This page shows all directory roles that can be assigned through PIM.

Step 3: Add a new role assignment

This opens the Add assignments wizard.

Step 4: Select the role and member

Step 5: Configure assignment type

Step 6: Complete the assignment

The user is now eligible for the Compliance Administrator role.

Part 2: Activate a Microsoft Entra role

Eligible users must activate a role before using its privileges.

Step 7: Open My roles

Step 8: Activate the role

Step 9: Complete security verification

Step 10: Provide justification and activate

The role is now temporarily active and will expire automatically based on role settings.

Part 3: Assign a role with restricted scope

Some Microsoft Entra roles support scoped assignments, limiting permissions to a specific boundary.

Step 11: Start a scoped assignment

Step 12: Review scope options

Exam note: Administrative units allow delegation without granting tenant-wide permissions.

Part 4: Update or remove an existing role assignment

Step 13: View current assignments

Step 14: Update an assignment

Step 15: Remove an assignment

The role assignment is removed immediately.

Key concepts to remember for the exam