An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
Hello @Tom Allen
The supported read-only method for Azure resource eligibility is the Azure Resource Manager roleEligibilityScheduleInstances API. At the resource-group scope you can query with:
$filter=assignedTo('<user-object-id>')
This returns eligibility for the user and exposes memberType values including Direct, Inherited, and Group. The response can contain nextLink, which must be followed for complete pagination.
The caller needs permission to read Azure role assignments at the relevant scope. Microsoft documents Microsoft.Authorization/roleEligibilityScheduleInstances/read, and the Az PowerShell implementation requires Microsoft.Authorization/roleAssignments/read.
However, PIM requires Microsoft Entra ID P2 or Microsoft Entra ID Governance. Microsoft also states that if the qualifying PIM license expires, eligible assignments for Azure resources are removed and the PIM portal, API, and PowerShell interfaces become unavailable.
Therefore, an AadPremiumLicenseRequired error is not itself an authoritative negative result. It means the PIM interface cannot provide the requested verification. If the ARM eligibility API also returns the licensing error, there is no supported read-only bypass under the current licensing state, so UNVERIFIED is the appropriate classification rather than assuming no eligible assignments exist.
If this answer helps, please mark it as Accepted/Resolved so it can help others as well.