You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/groups-activate-roles.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -35,7 +35,7 @@ When you need to take on a group membership or ownership, you can request activa
35
35
36
36
1. Using **Eligible assignments** blade, review the list of groups that you have eligible membership or ownership for.
37
37
38
-
:::image type="content" source="media/pim-for-groups/pim-group-6.png" alt-text="Review the list of groups that you have eligible membership or ownership for." lightbox="media/pim-for-groups/pim-group-6.png":::
38
+
:::image type="content" source="media/pim-for-groups/pim-group-6.png" alt-text="Screenshot of the list of groups that you have eligible membership or ownership for." lightbox="media/pim-for-groups/pim-group-6.png":::
39
39
40
40
1. Select **Activate** for the eligible assignment you want to activate.
41
41
@@ -45,7 +45,7 @@ When you need to take on a group membership or ownership, you can request activa
45
45
46
46
1. Depending on the group’s setting, justification for activation may be required. If required, provide it in the **Reason** box.
47
47
48
-
:::image type="content" source="media/pim-for-groups/pim-group-7.png" alt-text="Provide a justification in the Reason box." lightbox="media/pim-for-groups/pim-group-7.png":::
48
+
:::image type="content" source="media/pim-for-groups/pim-group-7.png" alt-text="Screenshot of where to provide a justification in the Reason box." lightbox="media/pim-for-groups/pim-group-7.png":::
49
49
50
50
1. Select **Activate**.
51
51
@@ -61,7 +61,7 @@ You can view the status of your pending requests to activate. It is specifically
61
61
62
62
1. Review list of requests.
63
63
64
-
:::image type="content" source="media/pim-for-groups/pim-group-8.png" alt-text="Review the list of requests." lightbox="media/pim-for-groups/pim-group-8.png":::
64
+
:::image type="content" source="media/pim-for-groups/pim-group-8.png" alt-text="Screenshot of where to review the list of requests." lightbox="media/pim-for-groups/pim-group-8.png":::
65
65
66
66
67
67
## Cancel a pending request
@@ -70,7 +70,7 @@ You can view the status of your pending requests to activate. It is specifically
70
70
71
71
1. Select **Azure AD Privileged Identity Management -> My requests -> Groups (Preview)**.
72
72
73
-
:::image type="content" source="media/pim-for-groups/pim-group-8.png" alt-text="Select the request you want to cancel." lightbox="media/pim-for-groups/pim-group-8.png":::
73
+
:::image type="content" source="media/pim-for-groups/pim-group-8.png" alt-text="Screenshot of where to select the request you want to cancel." lightbox="media/pim-for-groups/pim-group-8.png":::
74
74
75
75
1. For the request that you want to cancel, select **Cancel**.
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/groups-approval-workflow.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -32,7 +32,7 @@ As a delegated approver, you'll receive an email notification when an Azure reso
32
32
33
33
1. In the **Requests for role activations** section, you'll see a list of requests pending your approval.
34
34
35
-
:::image type="content" source="media/pim-for-groups/pim-group-9.png" alt-text="Requests for role activations." lightbox="media/pim-for-groups/pim-group-9.png":::
35
+
:::image type="content" source="media/pim-for-groups/pim-group-9.png" alt-text="Screenshot of requests for role activations." lightbox="media/pim-for-groups/pim-group-9.png":::
36
36
37
37
## Approve requests
38
38
@@ -42,7 +42,7 @@ As a delegated approver, you'll receive an email notification when an Azure reso
42
42
43
43
1. Select **Confirm**. An Azure notification is generated by your approval.
44
44
45
-
:::image type="content" source="media/pim-for-groups/pim-group-10.png" alt-text="An Azure notification is generated by your approval." lightbox="media/pim-for-groups/pim-group-10.png":::
45
+
:::image type="content" source="media/pim-for-groups/pim-group-10.png" alt-text="Screenshot of an Azure notification that is generated by your approval." lightbox="media/pim-for-groups/pim-group-10.png":::
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/groups-assign-member-owner.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,23 +37,23 @@ Follow these steps to make a user eligible member or owner of a group. You will
37
37
38
38
1. Select **Azure AD Privileged Identity Management -> Groups (Preview)** and view groups that are already enabled for PIM for Groups.
39
39
40
-
:::image type="content" source="media/pim-for-groups/pim-group-1.png" alt-text="View groups that are already enabled for PIM for Groups." lightbox="media/pim-for-groups/pim-group-1.png":::
40
+
:::image type="content" source="media/pim-for-groups/pim-group-1.png" alt-text="Screenshot of where to view groups that are already enabled for PIM for Groups." lightbox="media/pim-for-groups/pim-group-1.png":::
41
41
42
42
1. Select the group you need to manage.
43
43
44
44
1. Select **Assignments**.
45
45
46
46
1. Use **Eligible assignments** and **Active assignments** blades to review existing membership or ownership assignments for selected group.
:::image type="content" source="media/pim-for-groups/pim-group-3.png" alt-text="Screenshot of where to review existing membership or ownership assignments for selected group." lightbox="media/pim-for-groups/pim-group-3.png":::
49
49
50
50
1. Select **Add assignments**.
51
51
52
52
1. Under **Select role**, choose between **Member** and **Owner** to assign membership or ownership.
53
53
54
54
1. Select the members or owners you want to make eligible for the group.
55
55
56
-
:::image type="content" source="media/pim-for-groups/pim-group-4.png" alt-text="Select the members or owners you want to make eligible for the group." lightbox="media/pim-for-groups/pim-group-4.png":::
56
+
:::image type="content" source="media/pim-for-groups/pim-group-4.png" alt-text="Screenshot of where to select the members or owners you want to make eligible for the group." lightbox="media/pim-for-groups/pim-group-4.png":::
57
57
58
58
1. Select **Next**.
59
59
@@ -65,7 +65,7 @@ Follow these steps to make a user eligible member or owner of a group. You will
65
65
66
66
1. If the assignment should be permanent (permanently eligible or permanently assigned), select the **Permanently** checkbox. Depending on the group's settings, the check box might not appear or might not be editable. For more information, check out the [Configure privileged access group settings (preview) in Privileged Identity Management](groups-role-settings.md#assignment-duration) article.
67
67
68
-
:::image type="content" source="media/pim-for-groups/pim-group-5.png" alt-text="Configure the setting for add assignments." lightbox="media/pim-for-groups/pim-group-5.png":::
68
+
:::image type="content" source="media/pim-for-groups/pim-group-5.png" alt-text="Screenshot of where to configure the setting for add assignments." lightbox="media/pim-for-groups/pim-group-5.png":::
69
69
70
70
1. Select **Assign**.
71
71
@@ -77,15 +77,15 @@ Follow these steps to update or remove an existing role assignment. You will nee
77
77
78
78
1. Select **Azure AD Privileged Identity Management -> Groups (Preview)** and view groups that are already enabled for PIM for Groups.
79
79
80
-
:::image type="content" source="media/pim-for-groups/pim-group-1.png" alt-text="View groups that are already enabled for PIM for Groups." lightbox="media/pim-for-groups/pim-group-1.png":::
80
+
:::image type="content" source="media/pim-for-groups/pim-group-1.png" alt-text="Screenshot of where to view groups that are already enabled for PIM for Groups." lightbox="media/pim-for-groups/pim-group-1.png":::
81
81
82
82
1. Select the group you need to manage.
83
83
84
84
1. Select **Assignments**.
85
85
86
86
1. Use **Eligible assignments** and **Active assignments** blades to review existing membership or ownership assignments for selected group.
:::image type="content" source="media/pim-for-groups/pim-group-3.png" alt-text="Screenshot of where to review existing membership or ownership assignments for selected group." lightbox="media/pim-for-groups/pim-group-3.png":::
89
89
90
90
1. Select **Update** or **Remove** to update or remove the membership or ownership assignment.
:::image type="content" source="media/pim-for-groups/pim-group-19.png" alt-text="Screenshot of where to select Resource audit." lightbox="media/pim-for-groups/pim-group-19.png":::
40
40
41
41
1. Filter the history using a predefined date or custom range.
42
42
@@ -52,7 +52,7 @@ Follow these steps to view the audit history for groups in Privileged Identity M
52
52
53
53
1. Select **My audit**.
54
54
55
-
:::image type="content" source="media/pim-for-groups/pim-group-20.png" alt-text="Select My audit." lightbox="media/pim-for-groups/pim-group-20.png":::
55
+
:::image type="content" source="media/pim-for-groups/pim-group-20.png" alt-text="Screenshot of where to select My audit." lightbox="media/pim-for-groups/pim-group-20.png":::
56
56
57
57
1. Filter the history using a predefined date or custom range.
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/groups-discover-groups.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,11 +33,11 @@ You should either be a group Owner, have Global Administrator role, or Privilege
33
33
34
34
1. Select **Azure AD Privileged Identity Management -> Groups (Preview)** and view groups that are already enabled for PIM for Groups.
35
35
36
-
:::image type="content" source="media/pim-for-groups/pim-group-1.png" alt-text="View groups that are already enabled for PIM for Groups." lightbox="media/pim-for-groups/pim-group-1.png":::
36
+
:::image type="content" source="media/pim-for-groups/pim-group-1.png" alt-text="Screenshot of where to view groups that are already enabled for PIM for Groups." lightbox="media/pim-for-groups/pim-group-1.png":::
37
37
38
38
1. Select **Discover groups** and select a group that you want to bring under management with PIM.
39
39
40
-
:::image type="content" source="media/pim-for-groups/pim-group-2.png" alt-text="Select a group that you want to bring under management with PIM." lightbox="media/pim-for-groups/pim-group-2.png":::
40
+
:::image type="content" source="media/pim-for-groups/pim-group-2.png" alt-text="Screenshot of where to select a group that you want to bring under management with PIM." lightbox="media/pim-for-groups/pim-group-2.png":::
41
41
42
42
1. Select **Manage groups** and **OK**.
43
43
1. Select **Groups (Preview)** to return to the list of groups enabled in PIM for Groups.
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/groups-renew-extend.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -43,11 +43,11 @@ The following steps outline the process for requesting, resolving, or administer
43
43
44
44
Users assigned group membership or ownership can extend expiring group assignments directly from the **Eligible** or **Active** tab on the **Assignments** page for the group. Users or groups can request to extend eligible and active assignments that expire in the next 14 days.
:::image type="content" source="media/pim-for-groups/pim-group-11.png" alt-text="Screenshot of where to self-extend expiring assignments." lightbox="media/pim-for-groups/pim-group-11.png":::
47
47
48
48
When the assignment end date-time is within 14 days, the **Extend** command is available. To request an extension of a group assignment, select **Extend** to open the request form.
49
49
50
-
:::image type="content" source="media/pim-for-groups/pim-group-12.png" alt-text="Extend group assignment pane with a Reason box and details." lightbox="media/pim-for-groups/pim-group-12.png":::
50
+
:::image type="content" source="media/pim-for-groups/pim-group-12.png" alt-text="Screenshot of where to extend group assignment pane with a Reason box and details." lightbox="media/pim-for-groups/pim-group-12.png":::
51
51
52
52
>[!NOTE]
53
53
>We recommend including the details of why the extension is necessary, and for how long the extension should be granted (if you have this information).
@@ -56,19 +56,19 @@ Administrators receive an email notification requesting that they review the ext
56
56
57
57
To view the status of or cancel your request, open the **Pending requests** page for the group assignment.
58
58
59
-
:::image type="content" source="media/pim-for-groups/pim-group-13.png" alt-text="Pending requests page showing the link to Cancel." lightbox="media/pim-for-groups/pim-group-13.png":::
59
+
:::image type="content" source="media/pim-for-groups/pim-group-13.png" alt-text="Screenshot of the pending requests page showing the link to Cancel." lightbox="media/pim-for-groups/pim-group-13.png":::
60
60
61
61
### Admin approved extension
62
62
63
63
When a user or group submits a request to extend a group assignment, administrators receive an email notification that contains the details of the original assignment and the reason for the request. The notification includes a direct link to the request for the administrator to approve or deny.
64
64
65
65
In addition to using following the link from email, administrators can approve or deny requests by going to the Privileged Identity Management administration portal and selecting **Approve requests** in the left pane.
66
66
67
-
:::image type="content" source="media/pim-for-groups/pim-group-14.png" alt-text="Approve requests page listing requests and links to approve or deny." lightbox="media/pim-for-groups/pim-group-14.png":::
67
+
:::image type="content" source="media/pim-for-groups/pim-group-14.png" alt-text="Screenshot of the approve requests page listing requests and links to approve or deny." lightbox="media/pim-for-groups/pim-group-14.png":::
68
68
69
69
When an Administrator selects **Approve** or **Deny**, the details of the request are shown, along with a field to provide a business justification for the audit logs.
70
70
71
-
:::image type="content" source="media/pim-for-groups/pim-group-15.png" alt-text="Approve group assignment request with requestor reason, assignment type, start time, end time, and reason." lightbox="media/pim-for-groups/pim-group-15.png":::
71
+
:::image type="content" source="media/pim-for-groups/pim-group-15.png" alt-text="Screenshot of where to approve group assignment request with requestor reason, assignment type, start time, end time, and reason." lightbox="media/pim-for-groups/pim-group-15.png":::
72
72
73
73
When approving a request to extend a group assignment, resource administrators can choose a new start date, end date, and assignment type. Changing assignment type might be necessary if the administrator wants to provide limited access to complete a specific task (one day, for example). In this example, the administrator can change the assignment from **Eligible** to **Active**. This means they can provide access to the requestor without requiring them to activate.
74
74
@@ -78,7 +78,7 @@ If a user assigned to a group doesn't request an extension for the group assignm
78
78
79
79
To extend a group assignment, browse to the assignment view in Privileged Identity Management. Find the assignment that requires an extension. Then select **Extend** in the action column.
80
80
81
-
:::image type="content" source="media/pim-for-groups/pim-group-16.png" alt-text="Assignments page listing eligible group assignments with links to extend." lightbox="media/pim-for-groups/pim-group-16.png":::
81
+
:::image type="content" source="media/pim-for-groups/pim-group-16.png" alt-text="Screenshot of the assignments page listing eligible group assignments with links to extend." lightbox="media/pim-for-groups/pim-group-16.png":::
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/groups-role-settings.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,13 +37,13 @@ Follow these steps to open the settings for a group role.
37
37
38
38
1. Select the role you need to configure role settings for – **Member** or **Owner**.
39
39
40
-
:::image type="content" source="media/pim-for-groups/pim-group-17.png" alt-text="Select the role you need to configure role settings for." lightbox="media/pim-for-groups/pim-group-17.png":::
40
+
:::image type="content" source="media/pim-for-groups/pim-group-17.png" alt-text="Screenshot of where to select the role you need to configure role settings for." lightbox="media/pim-for-groups/pim-group-17.png":::
41
41
42
42
1. Review current role settings.
43
43
44
44
1. Select **Edit** to update role settings.
45
45
46
-
:::image type="content" source="media/pim-for-groups/pim-group-18.png" alt-text="Select Edit to update role settings." lightbox="media/pim-for-groups/pim-group-18.png":::
46
+
:::image type="content" source="media/pim-for-groups/pim-group-18.png" alt-text="Screenshot of where to select Edit to update role settings." lightbox="media/pim-for-groups/pim-group-18.png":::
0 commit comments