Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups.

MITAuto-check passedSecurity

Install Azure Pim

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-pim -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills azure-pim --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-pim .claude/skills/azure-pim && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-pim
GitHub stars
175
Token cost
~1.9k tokens
SKILL.md length
774 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups.

  • Works in 7 steps: Inventory permanent assignments — Use… → Convert to eligible in waves — Tier 2… → Configure activation settings per role —… → …
  • Entitlement management of resource access packages (use entra-id-governance)
  • SKILL.md covers When to use, Pick activation controls by…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Azure Pim is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups. Covers eligible vs active assignments, activation controls (MFA + approval + justification + ticket), access reviews, PIM for Groups, and removing standing access. WHEN: Privileged Identity Management, PIM, just-in-time access, time-bound role, eligible assignment, require approval to activate, privileged role activation, PIM…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Access reviews and audit trails. It works with Microsoft Azure and Microsoft Entra ID. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Entitlement management of resource access packages (use entra-id-governance)
  • Risk detection (use entra-id-protection)

Example prompts

  • “/azure-pim”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Inventory permanent assignments — Use Get-MgRoleManagementDirectoryRoleAssignment and
  2. Convert to eligible in waves — Tier 2 first (low blast radius if activation flow
  3. Configure activation settings per role — Match the tier table above. Phishing-resistant
  4. PIM for Groups — Use for privileged groups that aren't Entra roles (e.g. "Tier 0
  5. PIM for Azure resources — Onboard subscriptions and management groups. Convert Owner
  6. Recurring access reviews — Quarterly for Tier 0, bi-annually for Tier 1. Reviewer is
  7. Alerts and audit — Enable: "Too many global admins", "Roles activated outside PIM",

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Pim loads about 1.9k tokens when it runs. Until then it costs about 229 tokens; SKILL.md has 774 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~229
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 774 words, ~1,926 tokens.

Download SKILL.mdSave it as .claude/skills/azure-pim/SKILL.md (or your agent's skills folder).
name
azure-pim
description
Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups. Covers eligible vs active assignments, activation controls (MFA + approval + justification + ticket), access reviews, PIM for Groups, and removing standing access. WHEN: Privileged Identity Management, PIM, just-in-time access, time-bound role, eligible assignment, require approval to activate, privileged role activation, PIM for groups, access review privileged roles, reduce standing access, how do I remove permanent admin rights, temporary admin access, admins should not have standing Global Admin, JIT access for Azure roles, PIM activation alert, role activation audit. DO NOT USE for entitlement management of resource access packages (use entra-id-governance) or risk detection (use entra-id-protection).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Entra Privileged Identity Management (PIM)

PIM provides just-in-time, time-bound, approval-based, and audited elevation for privileged roles - eliminating standing administrative access and reducing the attack surface for high-value accounts. Requires Entra ID P2.

When to use

Governing privileged access to Entra roles, Azure RBAC roles, and privileged groups. Use this skill for moving permanent assignments to eligible, configuring activation controls, and running recurring access reviews.

Do not use this skill for resource access packages (entra-id-governance) or risk detection (entra-id-protection).

Pick activation controls by role tier

Role tierExamplesApprovalMFA strengthMax activation duration
Tier 0 - control planeGlobal Admin, Privileged Role Admin, Privileged Auth AdminRequired (2 approvers)Phishing-resistant1 hour
Tier 0 - AzureOwner on management group / root subscriptionRequiredPhishing-resistant2 hours
Tier 1 - workload adminExchange Admin, SharePoint Admin, Intune AdminRequired (1 approver)Phishing-resistant4 hours
Tier 1 - AzureOwner / Contributor on production subscriptionJustification + ticketMFA4 hours
Tier 2 - operationalHelpdesk, Reports Reader, Security ReaderJustificationMFA8 hours

Rule of thumb: the two-approver requirement on Global Admin is the single highest- value PIM control. It blocks self-elevation and forces a witness for every tenant-wide change.

Approach

  1. Inventory permanent assignments — Use Get-MgRoleManagementDirectoryRoleAssignment and the Azure portal Assignments view per subscription. Categorise by tier. Target: zero standing assignments outside break-glass. Verify: PIM → Entra roles → Assignments → Active shows only break-glass accounts for Global Admin.

  2. Convert to eligible in waves — Tier 2 first (low blast radius if activation flow breaks), then Tier 1, then Tier 0. Give admins 7 days notice + a walkthrough video. Verify: weekly activation count rises as expected; no admin complaints about lost access.

  3. Configure activation settings per role — Match the tier table above. Phishing-resistant MFA = require the authentication strength, not generic MFA. Verify: Global Admin activation requires 2 approvers and phishing-resistant strength.

  4. PIM for Groups — Use for privileged groups that aren't Entra roles (e.g. "Tier 0 Admins" group with multiple role assignments, AD-synced groups holding sensitive RBAC). Activate the group, not each role individually.

  5. PIM for Azure resources — Onboard subscriptions and management groups. Convert Owner and User Access Administrator to eligible. Scope time-bound assignments narrowly (resource group, not subscription, where possible).

  6. Recurring access reviews — Quarterly for Tier 0, bi-annually for Tier 1. Reviewer is the role assignee's manager, not the admin team. "No response" defaults to remove (with 24-hour grace period notification). Verify: review completion rate > 90%; removed assignments captured in audit log.

  7. Alerts and audit — Enable: "Too many global admins", "Roles activated outside PIM", "Activation doesn't require approval". Stream PIM audit (AuditLogs table) to Sentinel.

Show full SKILL.md (343 more words)Show less

Guardrails

  • Two break-glass accounts with permanent Global Admin, excluded from PIM. Monitored on every sign-in. If PIM has an outage, you still have a way in.
  • Two approvers for Global Admin activation. A single approver = self-approval if both approvers are admins. Two breaks that loop.
  • Phishing-resistant MFA for Tier 0 activation. SMS MFA at Global Admin elevation is unacceptable in 2026.
  • Time-bound, narrow scope for Azure RBAC. Resource group > subscription > management group. Tighter scope = lower blast radius if compromised.
  • Don't use "I just need it for a moment" as a justification. Audit the justifications - if they're meaningless, the control isn't working.
  • Access reviews quarterly minimum. Annual reviews allow 12 months of accumulated stale access.

Common anti-patterns

  • "Standing Global Admin for the IT team" - The exact attack surface PIM exists to eliminate. Move to eligible with approval.
  • "Approval optional - admins are trusted" - Removes the witness requirement and the audit trail. Always require approval for Tier 0.
  • "One approver" - Self-approval loop if the approver is also an admin. Two minimum.
  • "PIM for Entra roles only, Azure RBAC stays standing" - Cloud subscription Owner is the biggest blast radius in many tenants. Cover Azure too.
  • "Reviews once a year" - 12 months of drift. Quarterly for Tier 0.
  • "Justification field optional" - Without justification, the audit log loses context. Required everywhere.
  • "Use PIM for shared service accounts" - Service accounts can't approve interactively. Use managed identities + RBAC, not PIM.

Example prompts

  • Inventory standing admin assignments in our tenant and target zero outside break-glass.
  • Configure PIM activation for Global Admin with 2 approvers and phishing-resistant MFA.
  • Set up PIM for Azure resource roles (Owner on production subscription).
  • Configure quarterly access reviews for Tier 0 roles with auto-remove on no response.
  • Alert when a Global Admin is added outside PIM or activated more than 5 times a week.
  • Migrate our "Privileged Admins" security group to PIM for Groups.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-pim of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Azure Pim next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Pim compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Pim this skillvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Implementing Azure Ad Privileged Identity Managementmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.0
Detecting Azure Service Principal Abusemukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Implementing Identity Verification For Zero Trustmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0
Detecting Azure Lateral Movementmukul975/Anthropic-Cybersecurity-Skills34k—~808Automated safety check: PassApache-2.0
Attacking Entra Idtrilwu/secskills157—~4.3kAutomated safety check: PassMIT

Similar skills

  • Implementing Azure Ad Privileged Identity Management

    mukul975/Anthropic-Cybersecurity-Skills

    Configure Microsoft Entra Privileged Identity Management (PIM) to convert standing privileged assignments into eligible, time-bound roles requiring justification, MFA, and approval, covering Entra…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Azure Service Principal Abuse

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Identity Verification For Zero Trust

    mukul975/Anthropic-Cybersecurity-Skills

    Implements continuous, risk-adaptive identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with NIST SP…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Azure Lateral Movement

    mukul975/Anthropic-Cybersecurity-Skills

    Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation…

    34k GitHub stars~808 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Attacking Entra Id

    trilwu/secskills

    Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…

    157 GitHub stars~4.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Auditing Azure Active Directory Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Azure Pim

What does Azure Pim do?

Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups. Azure Pim is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups.

When should I use Azure Pim?

Azure Pim fits situations like: entitlement management of resource access packages (use entra-id-governance); risk detection (use entra-id-protection).

How do I install Azure Pim in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-pim -a claude-code`. Or copy the skill folder (skills/azure-pim in vinayaklatthe/microsoft-security-skills) into .claude/skills/azure-pim in your project. Claude Code loads it when a task matches its description.

How do I install Azure Pim in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-pim -a codex`. Or copy the skill folder (skills/azure-pim in vinayaklatthe/microsoft-security-skills) into .agents/skills/azure-pim in your project. Codex loads it when a task matches its description.

Can I use Azure Pim in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-pim -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-pim, .gemini/skills/azure-pim, .github/skills/azure-pim and .opencode/skills/azure-pim in your project.

What does Azure Pim need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Pim is instructions for the agent only.

Does Azure Pim access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Azure Pim safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Pim use?

Azure Pim is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Pim use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Pim?

Skills that share tags, products or a category with Azure Pim: Implementing Azure Ad Privileged Identity Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Azure Service Principal Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Identity Verification For Zero Trust (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Detecting Azure Lateral Movement (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Pim?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.