The AirGap Blueprints

One Activation, Every Role with PIM Groups

A Practical Guide to Just-in-Time Admin Access with PIM for Groups in Microsoft Entra ID

Get notified at launch

By Kevin Lanflo · Coming soon

Book cover: One Activation, Every Role with PIM Groups, by Kevin Lanflo. The AirGap Blueprints.

Admins keep their access because activating it is painful

When every role needs its own request, people ask for permanent assignments instead, and standing privilege quietly spreads across your tenant.

PIM for Groups changes that. Bundle the roles a job needs into one group, make people eligible, and a single time-bound activation grants everything they need for the task. Then it expires.

One activation time-bound · with MFA User Administrator Entra ID role Intune Administrator Entra ID role Security Reader Entra ID role Contributor Azure resource role App access Enterprise app role One activation time-bound · with MFA User Administrator Entra ID role Intune Administrator Entra ID role Security Reader Entra ID role Contributor Azure resource role App access Enterprise app role

Inside the book

  • Why standing access spreads, and how to measure it in your tenant
  • Designing groups around jobs, not individual roles
  • Eligible versus active, and when an exception is justified
  • Activation settings: MFA, justification, approval and duration
  • Protecting the groups themselves: role-assignable groups and owners
  • Reviews, alerts and audit that keep the model from drifting

About The AirGap Blueprints

The AirGap Blueprints is a series of cloud security strategy guides built on more than 25 years of real-world experience in the public and private sector. Each book takes one security challenge and turns it into a practical, risk-based standard you can plan, implement and adopt in your own environment.

What we learn has to be shared, or it leaves with us.

Written from the field

These are the approaches I recommend after planning, implementing and adapting security programs in real organizations, including the mistakes worth avoiding.

From plan to adoption

Every book follows the same structure: why it matters, how to plan it, how to implement it, and how to get people to adopt it and keep it working.

Shared with the profession

After 25 years of formal education and 25 years of work, this series is how I give that experience back to the community that taught me.

About the author

I'm Kevin Lanflo, a Senior Security Architect with 25 years of experience across the private and public sector. One Activation, Every Role is the approach I recommend after implementing privileged access in real organizations, written so you don't have to learn every lesson the hard way.

Be the first to read it

Send me a quick email and I'll let you know the day One Activation, Every Role is released. You can ask to be removed at any time.

Email me to join the launch list

Questions or organizational licensing: ebooks@airgapblueprints.com