Skip to content

Add Eligible Member To Role In Pim Completed

Azure

Add Eligible Member To Role In Pim Completed

service: Azure - Microsoft Entra ID
techniques:

Event

Creates eligibility for a Microsoft Entra role rather than an active role assignment. Permanent eligibility has no scheduled end, but activation remains subject to configured requirements such as approval, MFA, justification, and activation duration. Confirm role scope and schedule from PIM records.

Security Context

Unauthorized eligibility can support persistent or elevated access (T1098.003). Normal privileged-access administration uses the same workflow. Azure elevateAccess does not grant Privileged Role Administrator or Global Administrator in Entra, and eligibility does not prove activation or administrative use.

Log Source

Microsoft Entra directory audit logs. The sample uses activityDisplayName: Add eligible member to role in PIM completed (permanent). Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing. Preserve PIM completion and permanent/timebound distinctions; exact category/service serialization remains unverified.

Key Fields

FieldInvestigation value
targetResources[].modifiedPropertiesPrincipal, role, scope, eligibility, and expiration where recorded.
activityDisplayName, result, correlationIdCompletion versus request/approval/activation events; preserve permanent/timebound suffixes.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify assignment approval and the actor’s actual directory-role authority.
  3. Resolve the role definition, target principal, scope, eligibility schedule, and activation policy.
  4. Correlate later activation and privileged actions; permanent eligibility is not a permanently active role.

Sample Event

Synthetic scenario. The illustrative event records permanent Global Administrator eligibility for Draco. It does not establish prior elevation, activation, or successful privileged operations.

Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"id": "Directory_90000000-0000-4000-8000-000001100101_2B7E5_60718244",
"category": "RoleManagement",
"correlationId": "90000000-0000-4000-8000-000001100101",
"result": "success",
"resultReason": "",
"activityDisplayName": "Add eligible member to role in PIM completed (permanent)",
"activityDateTime": "2026-04-15T18:21:33.0884712Z",
"loggedByService": "PIM",
"operationType": "Add",
"initiatedBy": {
"app": null,
"user": {
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"userPrincipalName": "draco@fantasticlogs.cloud",
"ipAddress": "203.0.113.66"
}
},
"targetResources": [
{
"id": "30000000-0000-4000-8000-001010011010",
"displayName": "Draco Malfoy",
"type": "User",
"userPrincipalName": "draco@fantasticlogs.cloud",
"groupType": null,
"modifiedProperties": [
{
"displayName": "Role.DisplayName",
"oldValue": "[]",
"newValue": "[\"Global Administrator\"]"
},
{
"displayName": "Role.TemplateId",
"oldValue": "[]",
"newValue": "[\"62e90394-69f5-4237-9190-012177145e10\"]"
},
{
"displayName": "Role.ObjectId",
"oldValue": "[]",
"newValue": "[\"50000000-0000-4000-8000-000000000001\"]"
},
{
"displayName": "Member.Type",
"oldValue": "[]",
"newValue": "[\"User\"]"
},
{
"displayName": "Assignment.Scope",
"oldValue": "[]",
"newValue": "[\"/\"]"
},
{
"displayName": "Assignment.Type",
"oldValue": "[]",
"newValue": "[\"Eligible\"]"
},
{
"displayName": "Assignment.AssignmentState",
"oldValue": "[]",
"newValue": "[\"Eligible\"]"
},
{
"displayName": "Assignment.IsPermanent",
"oldValue": "[]",
"newValue": "[true]"
},
{
"displayName": "Included Updated Properties",
"oldValue": null,
"newValue": "\"Role.DisplayName, Role.TemplateId, Role.ObjectId, Member.Type, Assignment.Scope, Assignment.Type, Assignment.AssignmentState, Assignment.IsPermanent\""
}
]
},
{
"id": "50000000-0000-4000-8000-000000000001",
"displayName": "Global Administrator",
"type": "Role",
"userPrincipalName": null,
"groupType": null,
"modifiedProperties": []
}
],
"additionalDetails": [
{
"key": "RequestType",
"value": "AdminAdd"
},
{
"key": "User-Agent",
"value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)"
}
]
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: October 4, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.