A cloud-based identity and access management service for securing user authentication and resource access
If the role does not appear in PIM, check these points in order:
- Go to Microsoft Entra admin center > ID Governance > Privileged Identity Management > My roles.
- For Microsoft Entra role activation, the role must appear under My roles before it can be activated.
- If the assignment is approval-based, go to ID Governance > Privileged Identity Management > My requests.
- A pending activation request can appear there instead of as an active role.
- If needed, cancel the pending request and submit a new activation request.
- If activation requires MFA, PIM might not prompt again if MFA was already satisfied earlier in the session.
- In that case, review the PIM audit details to confirm MFA was required and satisfied.
- If the role is activated but access still does not appear in another admin portal, sign out and sign back in, or use a private browser session.
- Cached browser tokens can prevent the newly activated role from being recognized immediately.
- If the role still never appears under My roles, the supported guidance in the available documentation is only for activating roles that are already listed as eligible there. In that case, verify that the role was assigned as Eligible in PIM rather than expecting it to appear automatically after other account troubleshooting.
- Activate a Microsoft Entra role in PIM
- Privileged Identity Management - Role Activation MFA Settings Check - Microsoft Q&A
- Issues with PIM Access in M365 Admin Portal - Microsoft Q&A
- Privilege identity management does not work for a user due to the message "switch to an account that has permissions" - Microsoft Q&A