Setting up eligible PIM in large hub and spoke (ALZ) environment with several development teams. #85
LarsVidingSE
started this conversation in
General
Replies: 1 comment
-
|
Hi @LarsVidingSE sorry I missed your message. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
I shall deploy eligible PIM in a "large" Hub and spoke environment with scope to Azure subscription and resource groups and to several development team which has only eligible for their workloads and each team has two types of member roles. Member and System Architect. Each workload has four environment development, testing, acceptance and lastly production. My goal is to setup this via code.
We shall set this up for 6 different Azure RBAC roles. And we have 7 development teams and two member roles in each dev team.
The reader role shall be setup as permanent on scope Az Subscription level.
All the other will be eligible with require of MFA and only for 5 hours.
I have built a script that is importing all RBAC groups, member groups, Azure Roles, eligible Types and the scope level.
Today I have a problem with the eligible PIM.
Do you think that I will be more successful with your module and be able to use my source of truth which today is my excel file?
Beta Was this translation helpful? Give feedback.
All reactions