---
title: "Activating \"Just in Time\" Microsoft Admin Roles via Privileged Identity Management (PIM)"
canonical: "https://kb.uconn.edu/space/IKB/27342045238/Activating%20%22Just%20in%20Time%22%20Microsoft%20Admin%20Roles%20via%20Privileged%20Identity%20Management%20(PIM)"
format: markdown
---
Staff intended to have administrative roles in UConn’s Entra ID or Microsoft 365 environments are required to activate their role(s) using PIM. A PIM “Just in time” policy ensures that accounts only hold elevated privileges while they are necessary to perform administrative tasks.

> ✅ Navigate to or bookmark [https://entra.microsoft.com/#view/Microsoft_Azure_PIMCommon/ActivationMenuBlade/~/aadgroup](https://entra.microsoft.com/#view/Microsoft_Azure_PIMCommon/ActivationMenuBlade/~/aadgroup) to quickly access & elevate to your admin role via your PIM groups. Step by step instructions are below.

> ℹ️ Roles can be activated for up to 10 hours at a time.


## Steps to Activate

1. Navigate to [https://entra.microsoft.com](https://entra.microsoft.com) and login with your NetIDAdmin account.
2. Expand the **Identity Governance** section and click on **Privileged Identity Management** (PIM)
  1. Optionally pin PIM as a favorite by clicking the star icon to the right of its entry.
    
3. Click on **My roles** under the Tasks section on the left-hand side.
4. Then, click **Groups** in the Active section.
5. Click **Activate **next to the assigned group you wish to active roles for.

> 📝 If you are responsible for managing a PIM group in your area, you will see an additional **Owner** role row under Eligible assignments. You can activate this owner role to manage other assignments in that group. Please review [https://uconn.atlassian.net/wiki/spaces/IKB/pages/27372388353](https://uconn.atlassian.net/wiki/spaces/IKB/pages/27372388353) for more information on how to do so.

![image-20241212-195126.png](media://7609f8ed-c6d6-4f8c-affe-28dd55f405e5)

6. Specify a duration and provide a short justification, then click **Activate.**
7. Do not navigate away from this screen until the 3 activation steps complete as shown below. The roles associated with your PIM group will be added to your NetIDAdmin account for the duration you specified.

## Related Articles

> Macro (children)