Azure AD Role Assignment

Hi All,

When I assign an Administrator role to an Azure AD user, the user's Assignment Type is automatically set to Permanent in the Azure Portal. Is there a way to have 1IM set the Assignment Type to Eligible instead?

Thanks.

Parents
  • Hey Valiant,

    I have replied to your service request as well:

    It doesn't look like this can be configured on the 1IM side of things, out of box.

    As the documentation states, "Administrator roles are loaded into One Identity Manager by synchronization. You can edit individual master data of administrator roles but cannot create new administrator roles in One Identity Manager."

    So I think any change of assignment type has to be done on the Azure side of things.

    Although, I suppose it would be possible to add a custom column that could be mapped to the applicable attribute in Azure, and do it that way.

    Trevor

  • In addition to Trevor's reply, the assignment type you are referring to is part of Azure Active Directory (Azure AD) Privileged Identity Management (PIM) feature set which is an additional package in Azure and is currently not implemented in the current release version of the Graph API by Microsoft (only in the BETA stream). So currently, it is not supported OOTB to set the assignment type differently.

Reply Children
No Data