Enterprise Identity & Access Management Platform  ·  View 16 of 27  ·  Runtime

Privileged Elevation

How an administrator obtains production rights, and how they go away again.

Editable source SVG draw.io All views
Administrator
Administrator
Entra PIM
Entra PIM
Conditional Access
Conditional Access
Approver
Approver
Azure RBAC
Azure RBAC
Production resource
Production resource
Sentinel
Sentinel
1. activate Contributor, 4 h, ticket INC-4471
1. activate Contributor, 4 h, ticket INC-4471
2. evaluate activation policy
2. evaluate activation policy
3. phishing-resistant MFA + PAW met
3. phishing-resistant MFA + PAW met
4. approval request to 2 eligible approvers
4. approval request to 2 eligible approvers
5. approved with justification
5. approved with justification
6. create time-bound assignment
6. create time-bound assignment
7. active until 14:32 UTC
7. active until 14:32 UTC
8. elevated
8. elevated
9. perform the change
9. perform the change
10. authorize at scope
10. authorize at scope
11. allow
11. allow
12. expiry: remove assignment
12. expiry: remove assignment
13. request, approval, expiry events
13. request, approval, expiry events
14. alert: no ticket reference
14. alert: no ticket reference
15. denied — request closed, no access
15. denied — request closed, no access
Privileged Elevation — zero standing access
Privileged Elevation — zero standing access
Nobody holds the role between activations, so the compromise of an administrator account yields eligibility rather than privilege. Median activation is 3.2 per day and the approval path is the only path — PIM cannot be bypassed because the standing assignment does not exist to fall back on.
Nobody holds the role between activations, so the compromise of an administrator account yields eligibility rather than privilege. Median activation is 3.2 per day and the approval path is the only path — PIM cannot be bypassed because the standing assignment does not exist to fall back on.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display

Zero standing access

  • Nobody holds a privileged role between activations. Compromising an administrator account yields eligibility, which still has to survive MFA, a workstation check and a human approver.
  • PIM is the only path, not the preferred one. There is no standing assignment to fall back on, which is what makes the control real rather than procedural.
  • Activation is capped at four hours for production and requires a ticket reference. Expiry removes the assignment automatically — nothing depends on anyone remembering.

Numbers

  • 190 eligible role holders, median 3.2 activations per day, median approval time 6 minutes during business hours.
  • Tier 0 roles (Global Administrator, Privileged Role Administrator) require two approvers; tier 1 requires one. That asymmetry is the residual risk recorded in view 27.
  • PIM for Groups extends the same mechanism to Entra roles, Azure roles and application roles, so there is one elevation experience rather than three.

Detection

  • Activation without a valid ticket reference raises a Sentinel alert. It is not blocked, because a genuine emergency must not be stopped by a ticketing outage — it is made loud instead.
  • Approver compromise is a real vector: an attacker who phishes both requester and approver defeats the workflow. Two approvers on tier 0 and out-of-band notification limit it.
  • Out-of-hours activation is weighted higher in the alert score, and approval by the requester's direct report is rejected outright.