Entra ID

Entra PIM Custom Extensions Preview for Role Activation

2 min read

Summary

Microsoft has introduced preview support for custom extensions in Microsoft Entra Privileged Identity Management, allowing organizations to call a REST API during role activation to enforce business-specific rules. This helps IT teams automate checks such as ticket validation, HR status, compliance gates, and on-call logic while improving auditability and reducing manual approval gaps.

Need help with Entra ID?Talk to an Expert

Introduction

Microsoft is expanding Microsoft Entra Privileged Identity Management (PIM) with a new preview feature: custom extensions for role activation workflows. This matters because many organizations rely on business rules that live outside PIM, such as ITSM tickets, HR eligibility, compliance checks, or on-call schedules.

By letting PIM call a custom REST API during activation, Microsoft is giving IT and security teams a way to automate those checks directly in the approval flow instead of relying on disconnected manual processes.

What's new in PIM custom extensions

In preview, PIM custom extensions can be used to evaluate activation requests in real time during the pre-approval stage.

Key capabilities include:

  • REST API integration during role activation
  • Structured request payloads with details like principalId, roleDefinitionId, justification, ticketInfo, and scheduleInfo
  • Automated decisions returned by the API: Approved, AutoApproved, or Denied
  • Synchronous enforcement by PIM based on the API response
  • Audit logging with evaluationId, evaluationOutcome, and reason fields

Supported scenarios and scope

Microsoft says the preview supports:

  • PIM for Groups
  • PIM for Microsoft Entra roles
  • PIM for Azure resources

Example use cases include:

  • Validating a change or incident ticket against an ITSM platform
  • Confirming HR-based eligibility before allowing activation
  • Auto-approving access for users currently on call
  • Denying activation outside approved maintenance windows

Why this matters for admins

For Entra administrators, this feature closes a common governance gap. PIM already supports MFA, justification, and approvals, but many organizations still need external validation before privileged access is granted.

Custom extensions make those controls enforceable inside the activation workflow itself. That can improve least-privilege enforcement, reduce manual review overhead, and strengthen compliance evidence for audits or investigations.

Next steps

If you want to test the preview, Microsoft outlines five main steps:

  1. Build a custom extension REST API
  2. Secure it with Microsoft Entra ID
  3. Onboard the extension using Microsoft Graph API
  4. Link it to PIM role settings with Require pre-approval custom extension
  5. Test the full activation flow

Organizations already using external approval or validation processes should evaluate whether those checks can now be integrated directly into PIM. Since this is a preview, now is also a good time to validate scenarios and provide feedback to Microsoft.

Need help with Entra ID?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Entra IDPIMprivileged accessrole activationidentity governance

Related Posts

Entra ID

Microsoft Entra Passkeys for External IdP App Sign-Ins

Microsoft has made browser-based authentication for external identity providers generally available for supported Microsoft app sign-ins on Android, iOS, and managed macOS. This lets federated Microsoft 365 users use passkeys, FIDO2 security keys, and eligible SSO sessions in apps like Outlook, Teams, and OneDrive, reducing password fallback and embedded web view limitations.

Entra ID

Microsoft Entra Tenant Governance Webinars 2026

Microsoft is promoting upcoming webinars focused on securing multi-tenant environments with Microsoft Entra Tenant Governance, now generally available. The sessions highlight how organizations can detect shadow tenants, apply consistent governance, and build a stronger identity foundation for AI readiness.

Entra ID

Microsoft Entra App Gallery Self-Service Onboarding Preview

Microsoft has launched a public preview of self-service onboarding for new Microsoft Entra App Gallery applications. The new workflow lets publishers validate OIDC, SAML, and provisioning integrations before submission, then create, submit, and track app listings in the Entra admin center, reducing delays and rework.

Entra ID

Microsoft Entra Private Access Replaces VPNs

Microsoft is positioning Entra Private Access as a practical replacement for traditional VPNs, using identity-driven, per-app access instead of broad network tunnels. The guidance outlines a phased migration approach that helps IT teams reduce attack surface, strengthen Zero Trust controls, and simplify remote access operations.

Entra ID

HiBob Microsoft Entra Integration Now Generally Available

Microsoft has announced general availability of HiBob’s native integration with Microsoft Entra, enabling HR-driven identity lifecycle automation for joiners, movers, and leavers. The integration helps IT teams govern provisioning and access changes across hybrid and cloud environments while reducing manual processes and security risk.

Entra ID

Microsoft Entra September 2026: Key Identity Updates

Microsoft Entra's September 2026 updates introduce new tenant governance, user-centric access reviews, lifecycle workflow cloning, and passwordless resource accounts for Teams devices. The release also adds cloud-to-AD provisioning, AI-focused MCP Firewall protections, and important deadlines for MemberOf-based configurations and permission scope changes.