Skip to content

Manage Microsoft Entra PIM Role Assignments

The Entra ID roles area in MSPControl shows Microsoft Entra role assignments for one organization user in two views:

  • Eligible — roles the user can activate;
  • Active — roles that currently have an active assignment.

The current implementation can list assignments, create eligible or active assignments, activate an eligible assignment, update either assignment type, extend a time-bound active assignment, and remove an assignment.

You need:

  • access to the customer organization and the selected user;
  • MSPControl permission to edit the user;
  • a working Microsoft cloud connection for the organization;
  • Microsoft tenant configuration that permits the requested role-management operation.

MSPControl must be able to read the organization’s directory role templates before the Role selector can be populated. The exact Microsoft licensing and administrator-role matrix is tenant-dependent and is not defined by this procedure.

  1. Open the customer organization.
  2. Go to Active Users.
  3. Open the user you want to manage.
  4. Select Entra ID roles.
  5. Choose Eligible or Active.

Both views show the role name, user principal name, start time, and end time. MSPControl displays Permanent when the assignment has no end time.

  1. Open the Eligible view.
  2. Select Add Eligible Assignment.
  3. Select the directory role.
  4. Set the start time.
  5. Select Permanently assigned or set an end time.
  6. Submit the assignment.
  7. Wait for the table to reload and confirm that the role is listed.

The assignment type is fixed by the view from which the dialog was opened. The Justification field is not shown for an eligible assignment.

  1. Open the Active view.
  2. Select Add Active Assignment.
  3. Select the directory role.
  4. Set the start time.
  5. Select Permanently assigned or set an end time.
  6. Enter the justification requested by the dialog.
  7. Submit the assignment.
  8. Wait for the table to reload and confirm that the role is listed.
  1. Open the Eligible view.
  2. Find the role to activate.
  3. Select Activate Assignment.
  4. Review the fixed role and set the requested schedule.
  5. Enter a justification.
  6. Submit the activation.
  7. Open the Active view and verify the resulting assignment.

Use Update Assignment to change the schedule of an eligible or active assignment. The role and start time are fixed in the update dialog.

For a time-bound active assignment, Extend Assignment changes the end time while keeping the role and start time fixed. The extend action is not shown for an active assignment that has no end time.

After either action, verify the displayed schedule in the corresponding table.

  1. Open the Eligible or Active view that contains the assignment.
  2. Select Delete Assignment for the role.
  3. Confirm the deletion prompt.
  4. Wait for the table to reload.
  5. Confirm that the assignment is no longer listed in that view.

Removing an eligible assignment and removing an active assignment are separate operations. Verify the correct view before confirming the deletion.

After a create, activate, update, extend, or remove operation:

  1. Reload the relevant Eligible or Active view.
  2. Confirm the role and user principal name.
  3. Confirm the start time and end time, or Permanent when no end time is set.
  4. If you activated an eligible assignment, verify the result in the Active view.
  5. If the operation affects an administrative task, confirm the effective access in Microsoft Entra before relying on it.

Confirm that the organization Microsoft cloud connection is available and that MSPControl can retrieve directory role templates. Also review Microsoft consent and role-management permissions for the connected application.

Review the error displayed by MSPControl. Then verify the tenant’s Microsoft Entra licensing, role-management policy, consent, current assignment state, and permitted schedule. MSPControl sends the requested operation to Microsoft Graph; tenant policy remains authoritative.

The extend action is available only for an active assignment with an end time. Use Update Assignment for the other schedule changes exposed by the current view.

The table does not show the expected result

Section titled “The table does not show the expected result”

Reload the view and confirm that you are checking the correct assignment type. An eligible assignment and an active assignment can represent different states for the same role.