Azure Subscription: Email Notification for Administrative Role Activation

Receive Email Notifications for Azure Admin Role Activation

Question

You purchase an Azure subscription that is associated to a basic Azure Active Directory (Azure AD) tenant.

You need to receive an email notification when any user activates an administrative role.

What should you do?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

B

When key events occur in Azure AD Privileged Identity Management (PIM), email notifications are sent. For example, PIM sends emails for the following events:

-> When a privileged role activation is pending approval

-> When a privileged role activation request is completed

-> When a privileged role is activated

-> When a privileged role is assigned

-> When Azure AD PIM is enabled

https://docs.microsoft.com/en-us/azure/active-directory/privileged-identity-management/pim-email-notifications

To receive an email notification when any user activates an administrative role in Azure AD, you need to configure Azure AD Privileged Identity Management. Therefore, the correct answer is B: Purchase Azure AD Premium P2 and configure Azure AD Privileged Identity Management.

Azure AD Privileged Identity Management (PIM) is a service that enables you to manage, control, and monitor access to resources in Azure AD. It allows you to assign users to administrative roles for a limited time period, which reduces the risk of unauthorized access. When a user activates an administrative role, an email notification is sent to the designated recipients.

Azure AD Premium P2 provides advanced identity and access management features, including Azure AD PIM. You can purchase Azure AD Premium P2 as a standalone service or as part of the Microsoft 365 E5 or Enterprise Mobility + Security E5 subscriptions.

To configure Azure AD PIM, follow these steps:

  1. In the Azure portal, go to Azure Active Directory > Privileged Identity Management.
  2. Click on the Azure AD roles tab and select the role that you want to manage.
  3. Click on the Add assignments button to add users or groups to the role.
  4. Specify the duration for the role activation and the reason for the activation.
  5. Select the notification recipients who will receive an email notification when the user activates the role.
  6. Save your changes.

Once you have configured Azure AD PIM, you will receive an email notification when any user activates an administrative role in Azure AD. This helps you to monitor access to critical resources and take appropriate actions if necessary.