How to Automatically Remove Unused PIM Access After a Certain Time?

0
5
Asked By CuriousCactus92 On

I'm looking for a solution to automatically revoke a user's PIM access if they haven't been using it for a specific period. For instance, if someone hasn't elevated their access in two months, is there a way to set up a system that detects this inactivity and removes their access? Any advice or policies that could help? Thanks!

5 Answers

Answered By AccessNinja88 On

Regular access reviews might be your best bet. It seems that when people stop using a role, it’s usually for those rare, important tasks. Imagine suddenly losing access right when you need it—that could be a nightmare! So, regular checks might be smarter than an automatic removal policy.

Answered By CodeCrafter73 On

If you're logging PIM activations, you could create a PowerShell script to flag who hasn't elevated roles in a set number of days. That could make tracking inactivity easier!

Answered By TechTinkerer99 On

You might think about setting a specific time limit for how long access is valid. Automating it can save a lot of hassle down the line.

Answered By ScriptWizard45 On

You can actually use the alert features in PIM to help with this. By adjusting the settings, you can set alerts based on inactivity, like if someone hasn't signed in for a certain number of days. This way, you get notified when access should be evaluated or revoked. It’s a good way to keep track of things.

DataDynamo67 -

So you’re saying I can customize the alert settings to get notifications? That sounds super helpful!

Answered By ProactivePlayer43 On

Alternatively, is there a way to make PIM reactivation automatic when roles expire during working hours? That could save a lot of headaches when things get busy!

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.