Fabrikam currently assigns permanent Global Administrator and Security Administrator roles to several senior IT engineers. A recent internal audit flags this as a risk and recommends just-in-time access with approvals, alerts when privileged roles are activated, and regular reviews of who can elevate into admin roles.
A proposed design is to use Microsoft Entra Privileged Identity Management so that users are eligible for privileged roles but must activate them for a limited time with justification, MFA, and (optionally) approval, while auditors perform access reviews on those eligibilities.
Microsoft Entra Privileged Identity Management is specifically intended to reduce standing privileged access by providing just-in-time elevation, access reviews, and auditing for high-privilege roles.
