Concept and mechanism
An architecture should define who accesses what, which operations they can perform, and for how long. PIM helps reduce standing privilege through eligibility and controlled activation. Access reviews address another question: does the person still need access? Conditional Access uses identity conditions to decide application access but does not replace network filtering. Managed identities avoid managing application secrets; they still need destination authorization. Sharing an identity across workloads can combine permissions and complicate independent removal.
Guided application
Also design for failure of the administration mechanism itself. If everyone depends on the same federation and approvers, an outage can block recovery. Define an independent emergency path with strong authentication, protected credentials, monitoring, and rehearsal. At handover, record principal, scope, owner, activation, and removal. Test one allowed operation and another that should remain denied.
The service reads a secret through data permission; the platform team administers the vault through a separate grant.
Common pitfalls
Confusing authentication with authorization; using emergency accounts daily; making recovery depend on the failing component.
Related topics: Governance, cost, and observation · Relational data decisions
Least privilege and recoverable access should coexist in the design.
Reference: Privileged Identity Management · AZ-305 objectives 2026-04-17