Find privileged access beyond the admin list
An account is privileged when it can change or bypass a security control, not only when its name contains admin. A backup administrator, application owner or remote support identity can matter as much as a directory administrator.
Record the identity, owner, system, permissions, authentication method and reason for access. Include direct assignments, group membership and supplier access. Prioritise the accounts that can change other identities, security settings or recovery systems.
People and directory roles
Separate each administrator's daily account from their named admin identity. Match the role to a task, such as licence administration, rather than assigning Global Administrator by default.
Local device administrators
Check who can install software or change endpoint settings. Windows LAPS can manage a local administrator password; it does not remove every user's local admin membership.
Supplier and remote support access
List external engineers, support tools and the systems they can reach. Require an approved purpose, identifiable operator and a removal or expiry process.
Services, applications and agents
Record application identities, scheduled tasks and AI agents with elevated access. Give each an owner and review its permissions and credentials separately from human MFA.
PIM governs roles, not every privileged session
PAM is the wider operating practice: account ownership, least privilege, authentication, approval, credential handling, monitoring and recovery. Select controls against the systems you actually run rather than treating a single licence as complete coverage.
| Control | What it covers | What still needs work |
|---|---|---|
| PAM practice | Defines approved access, responsibilities and evidence across systems. | Needs implementation and an owner; a policy alone does not enforce it. |
| Microsoft Entra PIM | Temporary activation of eligible Entra roles, Azure resource roles and supported groups. | Does not automatically vault service passwords or record every remote session. |
| Windows LAPS | Manages and backs up a local administrator password on supported joined Windows devices. | Is not a complete endpoint privilege or service account management system. |
| Vaulting and session controls | Can manage secrets and record or broker supported administrative sessions. | Coverage, integrations, retention and licensing depend on the selected system. |
Different controls for different administrative risks
- Control
- PAM practice
- What it covers
- Defines approved access, responsibilities and evidence across systems.
- What still needs work
- Needs implementation and an owner; a policy alone does not enforce it.
- Control
- Microsoft Entra PIM
- What it covers
- Temporary activation of eligible Entra roles, Azure resource roles and supported groups.
- What still needs work
- Does not automatically vault service passwords or record every remote session.
- Control
- Windows LAPS
- What it covers
- Manages and backs up a local administrator password on supported joined Windows devices.
- What still needs work
- Is not a complete endpoint privilege or service account management system.
- Control
- Vaulting and session controls
- What it covers
- Can manage secrets and record or broker supported administrative sessions.
- What still needs work
- Coverage, integrations, retention and licensing depend on the selected system.
Grant the role for the task, then verify expiry
An eligible assignment allows a person to request activation; an active assignment gives them the role now. Configure authentication, justification, approval and duration per role. Confirm approvers are available before removing ordinary standing assignments.
Request a specific role
The administrator records the task, system and required duration. Choose the narrowest role that permits the work instead of requesting the broadest role available.
Verify the sign in
Apply the authentication and device requirements agreed for that role. Prefer supported phishing resistant methods and test enrolment and recovery before enforcement.
Approve sensitive activation
Require an appropriate approver for high impact roles. Link the reason to an approved change and make the fallback clear if the approver is unavailable.
Check expiry and the changes made
Verify the role returns to its expected state and review target system audit records. Expiry does not undo settings, new identities or persistent access created while the role was active.
Illustrative example, not a client result: a licence administrator activates the approved role for 60 minutes, assigns the agreed licence and lets the role expire. That is less standing access, not a measured percentage reduction in breach risk.
Keep emergency access outside the approval chain
Microsoft recommends two or more cloud only emergency access accounts using the tenant's onmicrosoft.com domain. Their Global Administrator assignments should be permanently active, not dependent on PIM activation. This is a controlled exception for recovery, not permission to use them for everyday work.
Separate the recovery dependencies
Do not make emergency access depend on the same federation, employee phone or approval chain that could fail for normal administrators. Secure and document access to the credentials.
Protect the emergency sign in
Microsoft recommends passkeys using FIDO2, or supported certificate authentication where appropriate. A Conditional Access exclusion does not remove Microsoft's mandatory MFA requirements.
Alert on use and changes
Assign a responder to emergency account sign in and audit alerts. Investigate unexpected use, including a change to credentials or role assignment.
Test recovery before removing access
Verify the recovery path and document authorised custodians before changing normal admin roles. Test again after relevant policy, personnel or authentication changes.
Reduce access without promising a breach cannot spread
A compromised account can still misuse an active role, seek approval by deception or change a system during an authorised session. PAM reduces opportunity and provides evidence; detection and response still need to cover identity and device activity.
Rotate credentials without breaking services
Map dependencies before changing a service password. Limit permissions, restrict interactive use where appropriate and test the application after rotation. Human PIM activation is not a universal control for automated workloads.
Restrict where administration happens
Use an approved administrative environment and limit its access to the services needed. A separate account on an exposed everyday device is not the same as separating the operating environment.
Collect the right evidence
Record role activations, role changes and target system actions. If recorded remote sessions are required, scope that capability explicitly; do not call activation history a session recording.
Review access when the work changes
Remove supplier access when the engagement ends and reassess permissions after departures or role changes. Agree a review schedule and record any continuing exception.
Map controls to the obligation that actually applies
Restricting administrative privileges is an Essential Eight mitigation. ASD's published maturity model includes just in time administration at Maturity Level Three, alongside other requirements. PIM alone does not establish an overall maturity level or satisfy every regulatory obligation.
| Source | Relevant requirement or guidance | Practical evidence |
|---|---|---|
| ASD Essential Eight | Validate privileged access and separate administration; higher levels add controls including just in time administration at ML3. | Approved requests, separate accounts and environments, access reviews and logs matched to the target level. |
| ASD ISM, September 2026 | System access guidance covers human and nonhuman identities; AI agents require distinct identities under ISM control 2133. | Owned identity register, permissions, recorded changes and an accountable operator or sponsor. |
| APRA CPS 234 | For entities in scope, security capability, controls and testing must match threats and asset criticality and sensitivity. | Documented scope, control design, testing and third party responsibilities; not a claim of compliance from one product. |
Australian guidance and the evidence to retain
- Source
- ASD Essential Eight
- Relevant requirement or guidance
- Validate privileged access and separate administration; higher levels add controls including just in time administration at ML3.
- Practical evidence
- Approved requests, separate accounts and environments, access reviews and logs matched to the target level.
- Source
- ASD ISM, September 2026
- Relevant requirement or guidance
- System access guidance covers human and nonhuman identities; AI agents require distinct identities under ISM control 2133.
- Practical evidence
- Owned identity register, permissions, recorded changes and an accountable operator or sponsor.
- Source
- APRA CPS 234
- Relevant requirement or guidance
- For entities in scope, security capability, controls and testing must match threats and asset criticality and sensitivity.
- Practical evidence
- Documented scope, control design, testing and third party responsibilities; not a claim of compliance from one product.
Recent source: ASD updated its Guidelines for system access on 3 September 2026. Include service, application and AI agent identities in the review. This is security guidance, not a statement that every Australian business is legally bound by the ISM. Insurance terms and critical infrastructure obligations need their own applicability check.
Agree the scope, test the change and review a month in
A scoped review should produce an access register, a prioritised change plan and a clear recovery procedure. Licences, integrations, maintenance windows and any specialist session controls are checked before you approve deployment.
- Step 1
Define the scope in the first call
We discuss your directory, devices, critical systems and existing suppliers. You identify system owners, business tasks and any contractual or regulatory requirements.
- Step 2
Approve the register and change plan
We identify privileged access and licensing dependencies in the agreed scope. You approve the owners, role changes, recovery design, costs and maintenance windows.
- Step 3
Pilot activation and recovery
We apply the agreed controls to a pilot and record results. Your administrators test real work, approvals, role expiry and emergency recovery before wider rollout.
- Step 4
Review a month into use
We review activation evidence, exceptions and the agreed controls. You confirm the roles still fit the work and approve remaining changes and the ongoing review schedule.
What we will not do
We will not remove the last working recovery path, rotate an untested service credential or give a routine licence task Global Administrator access for convenience. We will not describe PIM as a password vault, a complete session recorder or a guarantee against tenant compromise.
We will not promise insurance savings, certification or fixed delivery dates from a tool installation. Project work, additional licences and ongoing monitoring need a written scope; your current service agreement determines what is included.
Common questions
What is privileged access management?
Privileged access management controls elevated permissions across people, devices, applications and services. It combines ownership, least privilege, authentication, approval, credential handling, monitoring and recovery. Start with a register of who or what can change your systems or security controls.
What is the difference between PAM and Microsoft Entra PIM?
PAM is the wider practice; Microsoft Entra PIM is a role governance service within it. PIM supports eligible and active roles, temporary activation, approval and audit history for supported Microsoft resources. It does not automatically manage every service password, local admin account or recorded remote session.
Does Microsoft 365 Business Premium include PIM?
Business Premium includes Entra ID P1, not PIM by itself. Microsoft documents PIM entitlements through Entra ID P2 or Microsoft Entra ID Governance, including applicable bundles. Check the requirements for eligible users, approvers and the features used before buying or deploying licences.
Should every Global Administrator assignment be eligible?
No. Microsoft recommends two or more cloud only emergency access accounts with permanently active Global Administrator assignments. Normal administrators can use eligible roles where appropriate, but recovery must not rely on the activation or approval chain that could be unavailable.
Does PIM stop an attacker after role activation?
No. A compromised active role can still be misused, and expiry does not undo changes made during activation. Combine limited permissions and duration with strong authentication, an approved admin environment, target system audit evidence and detection and response.
Does installing PIM make us Essential Eight compliant?
No. PIM can support administrative privilege controls, including the just in time administration requirement at Maturity Level Three. The assessment must consider all requirements at your target level across all eight mitigations, including separate operating environments, monitoring and documented exceptions.
Start with an accurate admin access register
Our Brisbane team can scope a privileged access review for your Australian business. Bring your current identity platform, system owners and admin tasks, not passwords. We will agree the review, licensing checks and recovery requirements before recommending changes.

Remote Support