The AirGap Blueprints · A Cloud Security Strategy Guide

Launching October 21, 2026

One Activation, Every Role with PIM Groups

A Practical Guide to Just-in-Time Admin Access with PIM for Groups in Microsoft Entra ID

Notify me on launch day
Cover of One Activation, Every Role with PIM Groups by Kevin Lanflo

Why this book

Admins keep standing access because activating it is painful. This guide shows how to bundle the roles for each job into one PIM group, so a single time-bound, MFA-protected activation gives an admin everything the task needs — and permanent access stops being the easy option.

Start here: How to find standing Global Admins in Entra ID — a free field note from this book.

Who it's for

  • Identity and security architects designing privileged access in Entra ID
  • Microsoft 365 and Azure administrators tired of activating five roles one by one
  • Security leads who need to show auditors that standing privilege is shrinking

What's inside

  1. Measure how far standing access has spread before you change anything
  2. Design job-based groups around the work people actually do
  3. Choose between eligible and active assignments, and move people across
  4. Configure activation once per group: MFA, justification, approval and duration
  5. Protect the groups so they don't become the new back door
  6. Monitor, audit and review so the model keeps working

Built like every AirGap Blueprint

  • Rationale
  • Planning
  • Implementation
  • Adoption

Each guide takes one control from why it matters to running it in production, with the decisions, settings and review cadence written down — not just the clicks.