Add Eligible Member To Role In Pim Completed
Add Eligible Member To Role In Pim Completed
Event
Creates eligibility for a Microsoft Entra role rather than an active role assignment. Permanent eligibility has no scheduled end, but activation remains subject to configured requirements such as approval, MFA, justification, and activation duration. Confirm role scope and schedule from PIM records.
Security Context
Unauthorized eligibility can support persistent or elevated access (T1098.003). Normal privileged-access administration uses the same workflow. Azure elevateAccess does not grant Privileged Role Administrator or Global Administrator in Entra, and eligibility does not prove activation or administrative use.
Log Source
Microsoft Entra directory audit logs. The sample uses activityDisplayName: Add eligible member to role in PIM completed (permanent). Match target IDs and result, not a display name alone; Microsoft Graph-style JSON and Azure Monitor exports use different wrappers/casing. Preserve PIM completion and permanent/timebound distinctions; exact category/service serialization remains unverified.
Key Fields
| Field | Investigation value |
|---|---|
targetResources[].modifiedProperties | Principal, role, scope, eligibility, and expiration where recorded. |
activityDisplayName, result, correlationId | Completion versus request/approval/activation events; preserve permanent/timebound suffixes. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify assignment approval and the actor’s actual directory-role authority.
- Resolve the role definition, target principal, scope, eligibility schedule, and activation policy.
- Correlate later activation and privileged actions; permanent eligibility is not a permanently active role.
Sample Event
Synthetic scenario. The illustrative event records permanent Global Administrator eligibility for Draco. It does not establish prior elevation, activation, or successful privileged operations.
Exact field presence, modified-property names, payload nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "id": "Directory_90000000-0000-4000-8000-000001100101_2B7E5_60718244", "category": "RoleManagement", "correlationId": "90000000-0000-4000-8000-000001100101", "result": "success", "resultReason": "", "activityDisplayName": "Add eligible member to role in PIM completed (permanent)", "activityDateTime": "2026-04-15T18:21:33.0884712Z", "loggedByService": "PIM", "operationType": "Add", "initiatedBy": { "app": null, "user": { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "userPrincipalName": "draco@fantasticlogs.cloud", "ipAddress": "203.0.113.66" } }, "targetResources": [ { "id": "30000000-0000-4000-8000-001010011010", "displayName": "Draco Malfoy", "type": "User", "userPrincipalName": "draco@fantasticlogs.cloud", "groupType": null, "modifiedProperties": [ { "displayName": "Role.DisplayName", "oldValue": "[]", "newValue": "[\"Global Administrator\"]" }, { "displayName": "Role.TemplateId", "oldValue": "[]", "newValue": "[\"62e90394-69f5-4237-9190-012177145e10\"]" }, { "displayName": "Role.ObjectId", "oldValue": "[]", "newValue": "[\"50000000-0000-4000-8000-000000000001\"]" }, { "displayName": "Member.Type", "oldValue": "[]", "newValue": "[\"User\"]" }, { "displayName": "Assignment.Scope", "oldValue": "[]", "newValue": "[\"/\"]" }, { "displayName": "Assignment.Type", "oldValue": "[]", "newValue": "[\"Eligible\"]" }, { "displayName": "Assignment.AssignmentState", "oldValue": "[]", "newValue": "[\"Eligible\"]" }, { "displayName": "Assignment.IsPermanent", "oldValue": "[]", "newValue": "[true]" }, { "displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"Role.DisplayName, Role.TemplateId, Role.ObjectId, Member.Type, Assignment.Scope, Assignment.Type, Assignment.AssignmentState, Assignment.IsPermanent\"" } ] }, { "id": "50000000-0000-4000-8000-000000000001", "displayName": "Global Administrator", "type": "Role", "userPrincipalName": null, "groupType": null, "modifiedProperties": [] } ], "additionalDetails": [ { "key": "RequestType", "value": "AdminAdd" }, { "key": "User-Agent", "value": "python/3.11.6 (Linux-5.15.0-1052-aws-x86_64-with-glibc2.35) AZURECLI/2.56.0 (DEB)" } ]}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation Persistence
- T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...