Hello everyone. In today’s article, we’ll show you how to monitor requests and grants of privileged access using alerts and events in PIM. This article covers the “monitor privileged access” topic of the AZ-500 – Microsoft Azure Security Technologies exam. If you’re preparing to take this exam, don’t miss the upcoming articles on this blog.
Default alerts
Alerts are generated by Azure when there is some group access activity or suspicious activity in the environment. Let’s check the alerts generated in the environment in the next steps.
Checking alerts
If you haven’t yet enabled PIM on your Azure account, follow the steps in this link.
Access the Azure AD Roles menu in PIM through this link.
Sign in with your Azure credential.
Click Alerts.

Click Scan Now.

Let’s select the Roles are being assigned outsite of PIM alert.
Azure shows us the credentials that received privileged access without using PIM and the tool’s access grant control.
Let’s dismiss this alert by selecting the user Joseph and clicking Dismiss.

Now select the There are too many global administrators alert. This alert monitors the number of global administrators in Azure and flags when there are too many and a review is needed.
Let’s assume that the user Mantova no longer needs Global Admin access, and remove them from this role by clicking Fix selected.

The Potential stale accounts in a privileged role alert shows us the privileged accounts that haven’t had their passwords changed recently. It’s possible to identify and remove such accounts from the roles.

Configuring the default alerts
Now that we’ve identified the possibilities of Azure PIM alerts, let’s change some of the available parameters and show how to customize these alerts according to the company’s needs.
Access the Microsoft Entra ID role groups menu by clicking this link.
Click Settings and select Alerts.

Let’s change the Administrators aren’t using their privileged roles alert.
Click the alert you want to change.

Let’s change the amount of time a user can go without activating a role before it triggers a monitoring alert to 21 days.
Fill in the field with the number of days and click Save.
Click Save.

Directory role audit history
Another monitoring tool that can be used with PIM is Directory roles audit history, which lets us view privileged access activations graphically and in summary form. You can filter the view by time, action, and role, and export the chart data to a .csv file.

The My audit history menu shows the access grant activity of the user currently signed in to the Azure portal.

Summary
In today’s article, we showed how to monitor requests and grants of access to privileged groups managed by PIM using alerts and events.
With this article, we’ve wrapped up the subtopics related to the “Configure Microsoft Azure AD Privileged Identity Management” topic of the AZ-500 exam.
In the upcoming articles, we’ll cover the “Configure Microsoft Azure Active Directory for workloads” topic, starting with the subject of “how to configure MFA (Multi-factor Authentication) in Azure”.
I hope this content has contributed to enriching your knowledge of Azure.
Did you like the post? Like and share it. 🙂
If you have any suggestions or comments, let us know.
[ ]’s
Ulysses Neves
