Is it possible to receive notification emails when PIM (Privileged Identity Management) assignments are removed?

Shmuel Akura 0 Reputation points Microsoft Employee
2024-05-02T16:38:47.7+00:00

Hi all,

As a global administrator I'm receiving email notifications when users are assigned any PIM Entra roles.
However, when those user roles are removed by other administrators I'm not receiving any notifications.
Is there any configuration I can set to start receiving email notifications when roles are removed?

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
708 questions
Microsoft Entra
{count} votes

1 answer

Sort by: Most helpful
  1. David Broggy 5,701 Reputation points MVP
    2024-05-02T16:47:30.61+00:00

    Hi Shmuel,

    Yes you can receive notifications on any changes by sending your Azure Activity logs to Sentinel and setting up an analytical rule to email/notify you on the specified event.

    0 comments No comments