Hi All,
When I assign an Administrator role to an Azure AD user, the user's Assignment Type is automatically set to Permanent in the Azure Portal. Is there a way to have 1IM set the Assignment Type to Eligible instead?
Thanks.
Hi All,
When I assign an Administrator role to an Azure AD user, the user's Assignment Type is automatically set to Permanent in the Azure Portal. Is there a way to have 1IM set the Assignment Type to Eligible instead?
Thanks.
In addition to Trevor's reply, the assignment type you are referring to is part of Azure Active Directory (Azure AD) Privileged Identity Management (PIM) feature set which is an additional package in Azure…
30698 hence PIM support is still not part of the official MS API. In contrary the original MS Beta API has stopped working May 31, 2021 and has been replaced by a new MS Beta API.
Just as a reminder why…
Sorry, but I am unable to tell you anything about future planning around this topic. We are having this in our backlog and monitoring this closely is the best I can tell you at the moment.
If you want…
Hey Valiant,
I have replied to your service request as well:
It doesn't look like this can be configured on the 1IM side of things, out of box.
As the documentation states, "Administrator roles are loaded into One Identity Manager by synchronization. You can edit individual master data of administrator roles but cannot create new administrator roles in One Identity Manager."
So I think any change of assignment type has to be done on the Azure side of things.
Although, I suppose it would be possible to add a custom column that could be mapped to the applicable attribute in Azure, and do it that way.
Trevor
In addition to Trevor's reply, the assignment type you are referring to is part of Azure Active Directory (Azure AD) Privileged Identity Management (PIM) feature set which is an additional package in Azure and is currently not implemented in the current release version of the Graph API by Microsoft (only in the BETA stream). So currently, it is not supported OOTB to set the assignment type differently.
Trevor/Markus, thanks for the info.
Valiant
Hi Markus,
I am going to work on a very related topic and was wondering if you have any news regarding the status of the MS API and wether it supports eligible by now?
Thanks and Kind Regards, Dirk
Sorry, I currently have no further information on the status of the MS API.
Sorry, I currently have no further information on the status of the MS API.