Read this first — you can lock everyone out, and it's documented
PIM is the one tool in this suite that can remove your own ability to administer your tenant. Microsoft documents the exact combination, and every condition in it looks like good practice on its own:
- Every Global Admin and Privileged Role Admin is eligible, none active. Sensible — that's the whole point of PIM.
- Approval is required to activate. Also sensible — a second human on the highest privilege.
- No specific approvers are named. Easy to miss, because the field can simply be left empty.
With no approvers named, the default approver is an active Global Administrator or Privileged Role Administrator. By the first condition, there aren't any. Nobody can activate. Nobody can approve. Nobody can fix it.
The protection is one account: a break-glass account with a permanent active Global Administrator assignment, excluded from every Conditional Access policy, that you have actually signed in with. Not planned — tested. The Privileged Access Dojo owns that account's whole lifecycle, so the guidance lives in exactly one place.
- Look before you convert. Discovery and insights gives you a baseline you'll want later.
- One role at a time, and not Global Administrator first. Learn the flow where the blast radius is smaller.
- Eligible first, then remove the active assignment. Never leave someone with neither — least of all yourself.
- Name approvers explicitly, every time. An empty list is the trap above.
Full guidance: Configure Microsoft Entra role settings in PIM ↗
Size up your environment
Two questions. The licence answer is decisive here in a way it isn't elsewhere in the suite — PIM has no free or P1 tier, so if you don't have P2 or Governance this dojo will tell you honestly rather than scoring you against something you can't buy your way into halfway.
Do you manage Azure subscriptions and resource roles?
Walk out with a plan
Your plan reflects recorded answers and progress, including unresolved and deferred controls. Configuration examples require review of permissions, licensing, dependencies and placeholders. PowerShell bundles include an execution stop; read and edit them before deliberately running a selected section.