News

Microsoft Adds Privileged Identity Management Delegation to Azure Lighthouse

The commercial release of Privileged Identity Management (PIM)-enabled Azure Lighthouse delegations is now available, Microsoft on Monday announced.

The PIM-enabled delegations capability brings benefits to managed service providers using Azure Lighthouse, as well as their customers (or Azure "tenancies"). Microsoft had first previewed Azure AD PIM integration with Azure Lighthouse over a year ago, but now it's deemed ready for production use.

Azure Lighthouse is Microsoft's multitenant management solution that's mainly designed for use by managed service provider partners (MSPs) overseeing Azure services for customers. Microsoft also touts Azure Lighthouse use by enterprise organizations that are carrying out "cross-tenant management" tasks involving Azure services.

With PIM-enabled delegations in Azure Lighthouse, Azure tenancies can specify what their MSP can access, as well as the actions the MSPs can take. These Azure customers can also enforce multifactor authentication for MSP-managed tenancy access. Multifactor authentication entails providing another means of identity verification besides a password.

Another benefit for managed Azure tenancies is the ability to set "just-in-time" access delegations for MSPs, which grants service providers Azure tenancy access for a set period of time. The just-in-time option stems from the Azure Active Directory PIM integration with Azure Lighthouse, which also supports role-based access control designations. Azure tenancies can specify that certain IT personnel roles are required for managing various Azure resources.

To specify such details, Azure Lighthouse can tap an "eligible authorizations parameter," which "allows your customers to configure your just in time access policy, define your maximum activation duration, MFA provider (Azure), and approvers for eligible roles," the announcement explained. It's done using an Azure Resource Manager template, which surfaces these settings in Azure Lighthouse.

Azure tenancies can see Azure AD PIM activities via audit logs in the "Azure AD PIM blade," the announcement indicated.

The PIM-enabled delegations capability for Azure Lighthouse is also good for the MSPs overseeing Azure tenancies as it offers them "robust tooling" that's part of the Azure platform, Microsoft contended.

"With the addition of PIM eligible authorizations, customers and service providers have another tool to provide further granular level access to customer resources," the announcement indicated.

MSPs have certain licensing requirements to use the PIM-enabled delegations capability with Azure Lighthouse. They'll need to have "the Azure AD Premium P2 or EMS E5 license," Microsoft indicated.

The announcement did not list any licensing requirements for managed Azure customers to use PIM-enabled delegations.

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.

Featured

  • MIT Finds Only 1 in 20 AI Investments Translate into ROI

    Despite pouring billions into generative AI technologies, 95 percent of businesses have yet to see any measurable return on investment.

  • Report: Cost, Sustainability Drive DaaS Adoption Beyond Remote Work

    Gartner's 2025 Magic Quadrant for Desktop as a Service reveals that while secure remote access remains a key driver of DaaS adoption, a growing number of deployments now focus on broader efficiency goals.

  • Windows 365 Reserve, Microsoft's Cloud PC Rental Service, Hits Preview

    Microsoft has launched a limited public preview of its new "Windows 365 Reserve" service, which lets organizations rent cloud PC instances in the event their Windows devices are stolen, lost or damaged.

  • Hands-On AI Skills Now Outshine Certs in Salary Stakes

    For AI-related roles, employers are prioritizing verifiable, hands-on abilities over framed certificates -- and they're paying a premium for it.