Azure AD Privileged Identity Management (PIM) is an Azure AD Premium P2 or Enterprise Mobility + Security E5 feature. With PIM, you can manage and control all access inside the Azure AD tenant, such as access to Azure resources, Office 365, Intune, and Azure AD.
In RBAC, you can grant permanent role access. With PIM, you can grant eligible role access to users. Users that don't need permanent access to resources can request access for a predetermined amount of time when certain type of permissions are needed. For instance, a user can request temporary SharePoint Administrator permissions. This request can be approved by the Delegated Approver, and the permissions are deactivated when the user is done.
PIM uses the following flow:
- User Request: The users requests access using an online form for specific permissions for a predefined...