You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/pim-how-to-activate-role.md
+42-15Lines changed: 42 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,7 +11,7 @@ ms.service: active-directory
11
11
ms.topic: conceptual
12
12
ms.workload: identity
13
13
ms.component: pim
14
-
ms.date: 02/14/2017
14
+
ms.date: 08/21/2018
15
15
ms.author: rolyon
16
16
ms.custom: pim
17
17
---
@@ -26,25 +26,48 @@ This article is for admins who need to activate their role in Azure AD Privilege
26
26
Use the Azure AD Privileged Identity Management application in the [Azure portal](https://portal.azure.com/) to request a role activation, even if you're going to operate in another portal or PowerShell. If you don't have the Azure AD Privileged Identity Management application on your Azure portal, follow these steps to get started.
27
27
28
28
1. Sign in to the [Azure portal](https://portal.azure.com/).
29
-
2. Select your username in the upper right-hand corner of the Azure portal, and select the directory where you will you be operating.
30
-
3. Select **All services** and use the Filter textbox to search for **Azure AD Privileged Identity Management**.
31
-
4. Check **Pin to dashboard** and then click **Create**. The Privileged Identity Management application opens.
29
+
30
+
1. Select your username in the upper right-hand corner of the Azure portal, and select the directory where you will you be operating.
31
+
32
+
1. Select **All services** and use the Filter textbox to search for **Azure AD Privileged Identity Management**.
33
+
34
+
1. Check **Pin to dashboard** and then click **Create**. The Privileged Identity Management application opens.
32
35
33
36
## Activate a role
34
37
When you need to take on a role, you can request activation by selecting the **My Roles** navigation option in the Azure AD Privileged Identity Management application's left navigation column.
35
38
36
39
1. Sign in to the [Azure portal](https://portal.azure.com/) and select the Azure AD Privileged Identity Management tile.
37
-
2. Select **My Roles**. A list of your assigned eligible roles appear in the grouping at the top of the page.
38
-
3. Select a role to activate.
39
-
4. Select **Activate**. The **Request role activation** blade appears.
40
-
5. Some roles require Multi-Factor Authentication (MFA) before you can activate the role. You only have to authenticate once per session.
41
-
40
+
41
+
1. Select **My Roles**. A list of your assigned eligible roles appear in the grouping at the top of the page.
42
+
43
+
1. Select a role to activate.
44
+
45
+
1. Select **Activate**. The **Request role activation** blade appears.
46
+
47
+
1. Some roles require Multi-Factor Authentication (MFA) before you can activate the role. You only have to authenticate once per session.
48
+
42
49

43
-
6. Enter the reason for the activation request in the text field. Some roles require you to supply a trouble ticket number.
44
-
7. Select **OK**. If the role does not require approval, it is now activated, and the role appears in the list of active roles (directly below the list of eligible role assignments). If the [role requires approval](./azure-ad-pim-approval-workflow.md) to activate, a toast notification will briefly appear in the upper right-hand corner of your browser informing you the request is pending approval.
50
+
51
+
1. Enter the reason for the activation request in the text field. Some roles require you to supply a trouble ticket number.
52
+
53
+
1. Select **OK**. If the role does not require approval, it is now activated, and the role appears in the list of active roles (directly below the list of eligible role assignments). If the [role requires approval](./azure-ad-pim-approval-workflow.md) to activate, a toast notification will briefly appear in the upper right-hand corner of your browser informing you the request is pending approval.
Because of caching, activations do not occur immediately in the Azure portal without a refresh. If you need to reduce the possibility of delays after activating a role, you can use the **Application access** page in the portal. Applications accessed from this page check for new role assignments immediately.
1. Click **Azure Active Directory** to reopen the portal on the **All Users** page.
68
+
69
+
When you click this link, you force a refresh and there is a check for new Azure AD role assignments.
70
+
48
71
## Deactivate a role
49
72
Once a role has been activated, it automatically deactivates when its time limit (eligible duration) is reached.
50
73
@@ -54,10 +77,14 @@ If you complete your admin tasks early, you can also deactivate a role manually
54
77
In the event you do not require activation of a role that requires approval, you may cancel a pending request at any time. Simply select the **My Roles** navigation option in the Azure AD Privileged Identity Management application's left navigation column.
55
78
56
79
1. Sign in to the [Azure portal](https://portal.azure.com/) and select the Azure AD Privileged Identity Management tile.
57
-
2. Select **My Roles**. A list of your assigned eligible roles appear in the grouping at the top of the page.
58
-
3. Select a role.
59
-
4. Select the **Activation is pending approval** banner on the role activation details blade.
60
-
5. Select **Cancel** at the top of the **Pending approval** blade.
80
+
81
+
1. Select **My Roles**. A list of your assigned eligible roles appear in the grouping at the top of the page.
82
+
83
+
1. Select a role.
84
+
85
+
1. Select the **Activation is pending approval** banner on the role activation details blade.
86
+
87
+
1. Select **Cancel** at the top of the **Pending approval** blade.
Copy file name to clipboardExpand all lines: articles/active-directory/privileged-identity-management/pim-resource-roles-activate-your-roles.md
+15-2Lines changed: 15 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,15 +11,15 @@ ms.topic: conceptual
11
11
ms.tgt_pltfrm: na
12
12
ms.workload: identity
13
13
ms.component: pim
14
-
ms.date: 04/02/2018
14
+
ms.date: 08/21/2018
15
15
ms.author: rolyon
16
16
ms.custom: pim
17
17
---
18
18
19
19
# Activate roles for Azure resources by using Privileged Identity Management
20
20
Privileged Identity Management (PIM) introduces a new experience in activating roles for Azure resources. Eligible role members can schedule activation for a future date and time. They can also select a specific activation duration within the maximum (configured by administrators). For more information, see [How to activate or deactivate roles in Azure AD Privileged Identity Management](pim-how-to-activate-role.md).
21
21
22
-
## Activate roles
22
+
## Activate a role
23
23
Browse to the **My roles** section in the left pane. Select **Activate** for the role that you want to activate.
24
24
25
25

@@ -34,6 +34,19 @@ If the activation is scheduled for a future date and time, the pending request a
34
34
35
35

36
36
37
+
## Use a role immediately after activation
38
+
39
+
Because of caching, activations do not occur immediately in the Azure portal without a refresh. If you need to reduce the possibility of delays after activating a role, you can use the **Application access** page in the portal. Applications accessed from this page check for new role assignments immediately.
0 commit comments