Step-by-Step Information: setup conditional entry reauthentication coverage for PIM?


As soon as a person is authenticated by way of Entra ID, they continue to be signed in so long as the session is legitimate—even when they shut and reopen the browser. Nonetheless, in situations involving delicate duties or high-risk operations, it’s useful to require reauthentication. Forcing a contemporary sign-in provides an additional layer of safety by lowering the chance of session hijacking and token replay assaults. It additionally prevents attackers from sustaining persistence throughout companies and gadgets, limiting their skill to maneuver laterally throughout the surroundings.

A standard instance is when a person elevates their permissions to a higher-privileged function utilizing Entra ID Privileged Id Administration (PIM). By leveraging Conditional Entry reauthentication insurance policies, we will require customers to reauthenticate earlier than gaining privileged entry—including an vital layer of safety. On this weblog publish, I’ll Stroll by way of easy methods to configure this coverage step-by-step.

Excessive-Stage Configuration Duties

The next steps define the configuration course of for imposing reauthentication utilizing Conditional Entry and Privileged Id Administration (PIM):

  1. Create an Authentication Context in Conditional Entry.
  2. Replace Entra ID Privileged Id Administration (PIM) to affiliate the related function with the Authentication Context.
  3. Create a Conditional Entry coverage that enforces reauthentication primarily based on the outlined context.

Step 1: Create an Authentication Context

Authentication Context means that you can outline a label that represents a particular authentication requirement (e.g., MFA, compliant system, reauthentication). This label will be referenced in PIM configurations and Conditional Entry insurance policies.

To create an Authentication Context:

  1. Sign up to the Microsoft Entra admin heart.
  2. Navigate to Safety > Conditional Entry > Authentication context.
  3. Click on + New authentication context.

 

 

4.Within the creation pane, present a Identify and Description for the context.

 

 

5. Click on Save to create the context.

Step 2: Replace PIM Configuration

On this setup, the Safety Administrator function is already managed by way of Privileged Id Administration (PIM). For extra info on configuring PIM roles, check with the official documentation:
🔗 Configure Microsoft Entra PIM

 

 

The subsequent step is to affiliate the beforehand created Authentication Context with the PIM function to implement conditional entry insurance policies throughout function activation.

To replace PIM with Authentication Context:

  1. Sign up to the Microsoft Entra admin heart.
  2. Navigate to Id Governance > Privileged Id Administration, and choose the function you need to modify (on this instance, Safety Administrator).
  3. Click on on Settings.

 

 

4. Within the Function settings pane, choose Edit.

 

 

5. Beneath the On activation, require part, select Microsoft Entra Conditional Entry authentication context.

6. From the dropdown menu, choose the Authentication Context you created earlier.

 

 

7. Click on Replace to avoid wasting and apply the adjustments.

Step 3: Create a Conditional Entry Coverage to Implement Reauthentication

The ultimate step is to create a Conditional Entry coverage that forces reauthentication every time a person prompts a privileged function protected by the authentication context.

To create the Conditional Entry coverage:

  1. Sign up to the Microsoft Entra admin heart.
  2. Navigate to Safety > Conditional Entry.
  3. Click on + Create new coverage.

 

 

  1. Within the coverage creation pane:

o   Present a significant identify for the coverage.

o   Beneath Customers, choose the customers or teams this coverage ought to apply to.

o   Beneath Goal assets, select Authentication context, after which choose the context you created earlier.

 

 

 

  1. Go to the Session part and configure Signal-in frequency to Each time. This setting ensures that customers are prompted for reauthentication every time the context is invoked.

 

 

  1. Allow the coverage by toggling On, then click on Create to finalize it.

 

 

Testing the Configuration

With all of the required configurations in place, the subsequent step is to check the Conditional Entry reauthentication coverage in motion.

I signed in to the Azure portal utilizing a person account that’s eligible for the Safety Administrator function.

Navigating to PIM > My roles > Eligible assignments, I positioned the Safety Administrator function and clicked Activate.

 

 

At this stage, a message seems on the activation web page:
“A Conditional Entry coverage is enabled and will require further verification. Click on to proceed.”
No additional motion will be taken on this display till this immediate is addressed, so I clicked the hyperlink as instructed.

 

 

As anticipated, I used to be prompted to reauthenticate, according to the coverage we configured.

 

 

 

 

After efficiently reauthenticating, I used to be redirected again to the function activation web page, the place I may now enter the required justification and extra particulars.

 

 

Clicking Activate accomplished the function activation course of efficiently.

 

 

✅ This confirms that the Conditional Entry coverage imposing reauthentication is working as supposed for PIM function activation.

This concludes the weblog publish. I hope it has offered you with a transparent understanding of easy methods to configure and implement Conditional Entry reauthentication for Privileged Id Administration roles utilizing Authentication Context.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles