Skip to main content
Microsoft Solutions Partner — Security · 11,000+ engagements

Azure Bastion + PIM Privileged Access JIT Enterprise 2026

Zero standing administrative access across Azure — Bastion native RDP/SSH, Entra PIM eligible activation, Defender JIT VM access, Privileged Access Workstations, and the tiered admin model. Deployed end-to-end by a senior-architect-led Microsoft Solutions Partner founded in 1997.

What is Azure Bastion + Entra PIM + Just-in-Time VM access, and how do they eliminate standing privileged access in Azure? Azure Bastion is the Azure-native PaaS service that delivers browser-based RDP and SSH to virtual machines without a public IP or jump host. Entra Privileged Identity Management (PIM) is the activation-gate service that holds administrators as eligible rather than actively privileged, requiring MFA, approval, and time-bound activation before role permissions become effective. Defender for Cloud Just-in-Time VM access is the network-layer control that opens the management port only at the moment of activation and closes it automatically at expiry. Combined, the three services eliminate the two dominant production-Azure lateral movement vectors — standing-active role assignments and standing-open management ports — and produce the recorded session evidence that HIPAA, SOC 2, FedRAMP, FINRA, CMMC, and GxP auditors require.

Azure Bastion + Entra PIM + Defender JIT VM access is the Microsoft-native zero-standing-access stack for privileged operations in Azure. Bastion delivers browser-based RDP/SSH without public IPs. PIM holds administrators as eligible-only with MFA and approval gating. JIT opens the network port only at activation. EPC Group deploys all three plus the Tier 0/1/2 admin model and Privileged Access Workstations under a fixed-fee five-phase Accelerator.

Key Facts

  • Azure Bastion delivers native RDP/SSH from the browser or local client with no public IP on the target VM
  • Three Bastion SKUs — Basic (dev), Standard (production native client + IP-based), Premium (regulated session recording + private-only)
  • Entra PIM holds directory and Azure resource role assignments as eligible-only — activation requires MFA, justification, and approver workflow
  • PIM requires Entra ID P2 — included in Microsoft 365 E5, E5 Security, and the standalone P2 SKU
  • Defender for Cloud JIT VM access opens the NSG management port only at activation and closes it automatically at expiry
  • Tier 0/1/2 administrative model separates identity infrastructure (Tier 0), production workload (Tier 1), and endpoint/user-data access (Tier 2)
  • Privileged Access Workstation (PAW) enforced through Conditional Access — phishing-resistant MFA, Credential Guard, Application Control, compliant device
  • EPC Group Privileged Access Accelerator is fixed-fee $150K to $500K depending on Azure subscription count, privileged population, and regulatory scope
  • Microsoft Solutions Partner founded in 1997 — Security; 70+ Fortune 500 clients

Why standing administrative access is the dominant production-Azure attack vector

Standing administrative access — a role assignment that gives a user active production privilege every minute of every day regardless of whether the user is doing administrative work — is the single largest source of post-compromise lateral movement against production Azure in industry-wide incident response data. The attacker who phishes a cloud administrator does not need to escalate, does not need to forge tickets, does not need to abuse delegation. The compromised identity already holds the permissions; the attacker simply uses them.

The Microsoft-native answer is three services composed together. Azure Bastion replaces the legacy jump host and public-IP-exposed RDP/SSH with a browser-based or native-client-tunneled connection path that requires no public IP on the target VM and produces a recorded session in the Premium SKU. Entra Privileged Identity Management holds every administrator as eligible rather than active — the role permissions are not effective until the administrator requests activation, satisfies MFA and approval, and the activation window opens. Defender for Cloud Just-in-Time VM access closes the network-layer port until the moment of activation and reopens it for the duration of the request only.

The combined posture is what auditors mean when they say zero-standing-access. EPC Group ships this architecture as the default for every Azure estate in regulated industry, and increasingly as the default for unregulated estates where the executive team has read the latest Verizon Data Breach Investigations Report and understood that identity-layer attack is the dominant production breach pattern. The Microsoft Cloud Orchestrator hub describes the broader cloud orchestration model under which this pattern sits.

Azure Bastion — Basic, Standard, and Premium SKU

Three SKUs cover the spectrum from development estates through regulated production. The right SKU depends on the regulatory regime, the privileged population, and the concurrent-session scaling requirement.

Azure Bastion Basic SKU

Positioning: Entry-tier browser-based RDP/SSH for a single virtual network — the right floor for development and small production estates

  • Native RDP and SSH from the Azure portal over TLS 1.2 — no public IP on the target VM, no jump host, no client VPN
  • Per-virtual-network deployment with the dedicated AzureBastionSubnet (/26 minimum)
  • Two instance units fixed — predictable hourly cost, no scaling configuration
  • Identity-based access — RBAC Reader on the VM and Bastion host plus Virtual Machine User Login or Administrator Login for the connection

Azure Bastion Standard SKU

Positioning: Production-tier with native client tooling, host scaling, and the IP-based connection model that most enterprise estates need

  • Native client RDP/SSH from the local mstsc.exe or OpenSSH client through the az network bastion tunnel CLI
  • IP-based connection — reach on-premises VMs or non-Azure workloads reachable from the Bastion vnet, replacing legacy jump hosts
  • Instance scaling 2 to 50 units — concurrent session capacity grows linearly for large admin populations
  • Bi-directional file copy through the native client tunnel, audited through Azure Activity Log
  • Kerberos auth for AD-joined target VMs and shareable links for short-lived contractor access

Azure Bastion Premium SKU

Positioning: Regulated-industry tier with session recording, private-only deployment, and graph-based session policy — the SKU for HIPAA, FedRAMP, CMMC, FINRA, and GxP estates

  • Session recording with keystroke and screen capture stored in Azure Storage under customer-managed keys — auditor-grade evidence
  • Private-only Bastion deployment — Bastion host reached through Private Endpoint with no public IP
  • Graph-based session policies for granular per-target, per-user, per-time-window enforcement beyond RBAC
  • Inbound from internet disabled by default — administrators reach Bastion through ExpressRoute, Virtual WAN, or Private Endpoint

Entra Privileged Identity Management — eligible, active, approval, review

PIM is the activation-gate architecture that holds administrators as eligible rather than active. Four mechanics combine to produce the zero-standing-access posture — eligible assignments, constrained active assignments, approval workflows, and periodic access reviews.

Eligible assignments — the activation gate

Role: A user holds the role on paper but does not carry the permissions until activation under approval

  • Eligible assignment grants the right to request activation, not the active permissions — the user is unprivileged until activation completes
  • Maximum activation duration configurable per role (1 to 8 hours typical, 30 days maximum under exception)
  • Activation requires MFA on the request, optional justification text, and optional named approver workflow
  • Eligible-only is the EPC Group default for every directory role and every Azure resource role above Reader

Active assignments — the constrained exception

Role: Standing permissions that bypass the activation gate, reserved for break-glass and a small number of service identities

  • Two break-glass Global Administrator accounts stored under sealed-envelope custody, excluded from Conditional Access and PIM
  • Service principals and managed identities cannot be eligible — they require scoped active assignment by design
  • Time-bound active assignment (start and end date) for short-window scenarios — vendor cutover, regulator-directed access — never indefinite
  • Every active assignment surfaces in the PIM access review queue with quarterly attestation from the resource owner

Approval workflows — separation of duties at activation

Role: Named approvers gate every privileged-role activation, with full audit trail and Conditional Access enforcement on the approver action

  • Per-role approver list — Global Admin activation can require two named approvers, Application Admin one, Reader none
  • Approval routes to Teams, Outlook, and the Entra portal with requester justification, duration, and recent activity context
  • Approver action requires phishing-resistant MFA, compliant device, and named-location enforcement on the approver session
  • Approval and activation events flow into the Entra audit log, Sentinel, and the Defender XDR incident graph

Access reviews — the periodic re-justification

Role: Eligible and active assignments expire under access review unless the resource owner explicitly re-justifies

  • Quarterly access review for every directory role and every Azure resource role above Reader — requester, approver, resource owner, and role are all re-attested
  • Self-review with manager override is the EPC Group default; the resource owner can override either decision
  • Auto-removal of inactive eligible assignments — the EPC default is 90 days without activation triggers automatic removal
  • Access review evidence packaged into SOC 2 CC6.1 attestation and HIPAA §164.308(a)(4) workforce authorization records

Six enterprise privileged-access patterns

Every EPC Group Privileged Access Accelerator composes from six patterns that recur across every estate — the admin workstation pattern, contractor JIT, MSP delegated admin, regulated-industry break-glass, M&A cross-tenant temporary admin, and production zero-standing-access for the platform team.

Pattern 1 — The Privileged Access Workstation (PAW) admin pattern

Every Tier 0 administrator reaches privileged systems from a dedicated Privileged Access Workstation — a hardened, single-purpose endpoint with Windows Hello for Business, Credential Guard, Application Control, and Defender for Endpoint EDR. EPC Group composes the pattern as Conditional Access (compliant device required, sign-in risk low, named location matches the PAW corporate VLAN) plus Bastion as the only outbound administrative path plus PIM as the activation gate. The Tier 0 admin authenticates to the PAW with FIDO2, requests PIM activation, satisfies the named approver workflow, opens Bastion in the browser, and reaches the target VM in a recorded session. The general-purpose laptop the same person uses for email and Teams cannot reach any of those resources — the Conditional Access policy denies the connection by device-compliance signal alone.

Pattern 2 — Third-party contractor JIT access with sealed expiry

Third-party contractors and short-term consultants are the most common standing-access risk in enterprise Azure estates — a vendor account granted Contributor on a resource group in 2022 that no one has reviewed since. EPC Group eliminates the exception by sealing every contractor at the PIM eligible tier with a short maximum activation window (typically 4 hours), an approver workflow that routes to the contractor sponsor, and an access review that auto-removes eligibility after 30 days without activation. Bastion replaces the legacy site-to-site VPN so the contractor reaches the target VM through a recorded browser session without a credential ever landing on the contractor laptop. When the engagement ends, the eligible assignment expires automatically and the audit evidence packages cleanly into SOC 2 and HIPAA review.

Pattern 3 — MSP delegated administration with cross-tenant PIM

Microsoft partner (MSP) engagements depend on cross-tenant administrative access. The modern path is Granular Delegated Admin Privileges (GDAP), where the partner holds time-bound, role-scoped delegated access into the customer tenant rather than the legacy DAP unrestricted Global Administrator. EPC Group composes the MSP pattern as customer-side PIM eligible assignment for the partner administrators (constrained by GDAP role mapping), Bastion deployed in the customer tenant as the only administrative path into customer VMs, and a partner-side activation workflow that requires the partner administrator to satisfy customer-side Conditional Access before activation completes. The customer retains the audit log, the recorded session evidence, and the activation history regardless of which partner organization the administrator belongs to.

Pattern 4 — Regulated-industry break-glass and recovery access

Every regulated tenant needs a break-glass path for the case when Conditional Access, PIM, MFA, or the broader identity layer is itself the problem. The standard EPC Group break-glass design is two cloud-only Global Administrator accounts excluded from Conditional Access, excluded from PIM, never used for routine work, never assigned to a named human, stored under split-knowledge custody between two officers, and monitored by a Microsoft Sentinel analytics rule that fires the moment either account signs in. The pattern combines with Bastion for the recovery connection path (so even break-glass actions are recorded), with quarterly break-glass exercise, and with PAW enforcement for the recovery laptop. The pattern is a HIPAA §164.308(a)(7) Contingency Plan requirement, a SOC 2 CC7.4 incident-response control, and a FedRAMP IR-4 documentation artifact.

Pattern 5 — M&A cross-tenant temporary administrative access

M&A integration creates the most complex temporary administrative access challenge in the Microsoft cloud — administrators from the acquiring company need limited, time-bound access into the acquired tenant for the duration of integration, with no permanent grant. EPC Group has executed this pattern across more than two hundred tenant consolidations. The construction is Azure Lighthouse for cross-tenant Azure resource access (eligible-only delegated assignment), Entra ID B2B collaboration for cross-tenant identity, PIM eligible-only activation on the acquiring side that satisfies both tenants Conditional Access, Bastion deployment in the acquired tenant during cutover, and an integration end-date hard stop that auto-removes every delegated assignment and guest account when the project closes.

Pattern 6 — Production zero-standing-access for the platform team

The platform team that operates production Azure for a large enterprise is the highest-leverage privileged access population in the tenant. The EPC Group default architecture is zero standing access — every platform engineer is eligible-only with PIM, activation requires named approver from a separate engineer (two-person rule), the maximum activation window is four hours, and every activation generates a Bastion-only path to the target resources. Routine work that does not require privileged access happens through Azure Monitor read-only views, Log Analytics queries against Sentinel, and Cost Management dashboards the engineer holds permanently. Defender for Cloud JIT VM access layers underneath, opening the network path only at activation and closing it automatically at expiry. The combined posture eliminates the standing-active permissions that are the single largest source of post-compromise lateral movement against production Azure.

Defender for Cloud — JIT VM access

Defender for Cloud JIT VM access — the network-layer pair to Bastion + PIM

Defender for Cloud Just-in-Time VM access is the third layer that completes the zero-standing-access stack. JIT governs the network-layer permission to reach the VM — the NSG rule on the management port — and gates it behind an approval workflow with automatic close after the requested time window. Bastion governs the session path; PIM governs the identity activation; JIT governs the network exposure. Together they eliminate both the network-layer standing exposure and the session-layer standing access.

NSG-layer port gating

Management ports (3389, 22, 5985, and any custom administrative port) closed by default; opened by JIT only at activation and only from the requester source IP for the approved time window.

Approval-gated request flow

Request flow integrates with PIM and Conditional Access — the requester satisfies MFA on activation, the approver satisfies Conditional Access on the approval action, the audit trail captures both.

Defender XDR fusion

JIT request events join the Defender for Cloud CNAPP incident graph alongside Bastion sessions and PIM activations — one timeline per privileged operation.

PAW + Tiered admin model

Privileged Access Workstation and the Tier 0/1/2 administrative model

Bastion and PIM solve the activation and session problem; the Privileged Access Workstation and the tiered administrative model solve the originating-device problem. A Tier 0 administrator who activates PIM from an unmanaged laptop with email and consumer apps installed has handed the attacker the same activation gate. The PAW plus tiered admin model closes the gap.

Tier 0 — identity infrastructure

Domain controllers, Entra ID directory roles (Global Admin, Privileged Role Admin), AD FS, AD CS, PIM administration. Access only from PAW with FIDO2, Credential Guard, Application Control, named-location enforcement.

Tier 1 — production workload

Production Azure subscriptions, application servers, production data stores. Access from compliant managed device with phishing-resistant MFA; PIM activation required; Bastion-only path; JIT VM access enforced.

Tier 2 — endpoint and user data

Help-desk, endpoint management, user data administration. Access from compliant managed device with MFA; separation from Tier 0 and Tier 1 enforced by Conditional Access device-compliance and named-location policies.

PAW build standard

Windows 11 Enterprise, Windows Hello for Business with FIDO2, Credential Guard, Hypervisor-protected Code Integrity, Microsoft Defender Application Control, Defender for Endpoint EDR, BitLocker with TPM 2.0, Autopilot-provisioned.

Conditional Access enforcement

PAW devices tagged in Intune; Conditional Access policies require the PAW device tag for any Tier 0 activation. The general-purpose laptop fails the policy and cannot complete activation regardless of the user identity behind it.

Separation of duties

Tier 0 admins hold no Tier 1 standing access and no Tier 2 standing access; Tier 1 admins hold no Tier 0 standing access. A compromised Tier 2 help-desk account cannot escalate into the directory plane without an entirely separate compromise.

See the AI Identity Security services page for the broader identity protection architecture in which this tiered model sits.

The EPC Group Privileged Access Accelerator — five phases, fixed fee

The accelerator anchors on The EPC Group Lifecycle — Assess, Activate, Harden, Hunt, Operate. Fixed-scope between $150,000 and $500,000 depending on Azure subscription count, privileged-user population, regulatory requirements, tiered-admin scope, and managed-service tail. Senior-architect led, no offshore handoff.

Phase 1 — Assess

Privileged access attack-surface assessment in three weeks

Phase one inventories every standing administrative assignment across Entra ID directory and Azure resource roles, every legacy jump host and public-IP-exposed VM, every contractor account holding role assignment beyond engagement end-date, and every break-glass and service-principal assignment bypassing governance. EPC Group ships a costed roadmap, a risk-weighted attack-path backlog, and a Tier 0/1/2 cleanup plan aligned to NIST CSF 2.0 Protect and HIPAA §164.308(a)(4).

  • Entra ID role assignment inventory — Global Admin, Privileged Role Admin, Security Admin, and every directory role with standing-active grants
  • Azure resource role inventory — Subscription Owners, Management Group Contributors, and every standing role above Reader on production resource groups
  • Jump host and public-IP surface inventory — every Windows or Linux VM with RDP/SSH exposed to internet or to broad corporate network ranges
  • Privileged Identity Secure Score baseline and PIM readiness assessment sequenced by attack-path criticality

Phase 2 — Activate

Bastion deployed, PIM live, JIT enabled

Phase two deploys Bastion (SKU sized to regulatory and scaling requirements), activates Entra PIM across directory and Azure resource roles, and enables Defender for Cloud JIT VM access on production. EPC Group starts with a pilot subscription and a single privileged role, then broad-rolls under change control. Break-glass accounts are provisioned and sealed under two-person custody before legacy standing-access grants are removed.

  • Azure Bastion deployment in the hub virtual network (Standard or Premium SKU per regulatory requirement)
  • Entra PIM activation for every directory role and every Azure resource role above Reader — eligible-only default
  • Defender for Cloud JIT VM access enabled across production subscriptions with port-time-window approval gating
  • Break-glass accounts provisioned, sealed envelope process documented, Sentinel analytics rule activated for break-glass sign-in detection

Phase 3 — Harden

Tier 0/1/2 admin model and PAW enforcement live

Phase three is the hardening that turns activation into defense. EPC Group deploys the tiered administrative model (Tier 0 identity, Tier 1 workload, Tier 2 endpoint) with separation enforced through Conditional Access device-compliance and named-location policies. PAWs are deployed for every Tier 0 admin with Windows Hello for Business, Credential Guard, Application Control, and Defender EDR. Legacy public-IP RDP/SSH exposure is removed; Bastion becomes the only administrative path.

  • Tiered admin model — Tier 0, Tier 1, Tier 2 separation enforced by Conditional Access device-compliance and named-location policies
  • Privileged Access Workstation (PAW) deployment for every Tier 0 administrator with Windows Hello for Business and Application Control
  • Public-IP RDP/SSH removal across every production VM — Bastion-only administrative path enforced
  • Conditional Access — phishing-resistant MFA required for every PIM activation, sign-in risk-based session controls, compliant device required

Phase 4 — Hunt

Privileged-access threat hunting with Sentinel and Defender XDR

Phase four stands up threat hunting for privileged access. EPC Group authors KQL queries against SigninLogs, AuditLogs, AzureActivity, and PIM activation tables, builds saved libraries for the MITRE ATT&CK Privilege Escalation and Credential Access tactics, and configures Sentinel to ingest Bastion session logs and PIM activation events for cross-source correlation. SOAR playbooks automate the high-confidence response actions.

  • KQL hunting library — anomalous PIM activation patterns, after-hours administrative activity, Bastion file-copy anomalies
  • Microsoft Sentinel data connectors for Bastion session logs, PIM activation events, and Defender for Cloud JIT VM access requests
  • Custom analytics rules — break-glass sign-in detection, two-person-rule violation detection, after-expiry privileged-action detection
  • SOAR playbooks for the top fifteen privileged-access incident scenarios — emergency session termination, role revocation, account isolation

Phase 5 — Operate

24/7 managed privileged access with senior-architect escalation

Phase five is steady-state. EPC Group provides managed privileged access — 24/7 monitoring of PIM activations, Bastion Premium session reviews, quarterly access reviews with documented attestation, break-glass exercise execution under controlled change, and Identity Secure Score campaign management. Senior-architect escalation is the differentiator; tier-one analysts triage, but every customer has named senior architects on call for Tier 0 incidents and break-glass events.

  • 24/7 SOC monitoring of PIM activations, Bastion sessions, and JIT VM access requests
  • Quarterly access reviews with documented evidence packaged for SOC 2, HIPAA, FedRAMP, and CMMC auditors
  • Quarterly break-glass exercise under controlled change — proves the sealed envelope works without consuming it
  • Identity Secure Score campaign management — monthly delta tracking, posture improvement work, executive reporting

Why EPC Group leads enterprise Privileged Access deployments

1997
Founded · Microsoft consulting
70+
Fortune 500 clients
216+
M&A tenant consolidations
1.83 million
Users migrated

Microsoft Solutions Partner — Security

Microsoft Solutions Partner with the Security designation plus five additional designations covering Modern Work, Infrastructure, Data & AI, Digital & App Innovation, and Business Applications. Senior identity architects average two decades of Active Directory and Entra ID delivery experience.

Four-time author for Microsoft Press and Sams

Founder Errin O’Connor has nearly three decades of Microsoft consulting leadership and is a four-time author for Microsoft Press and Sams across Power BI and SharePoint.

Fixed-fee accelerators

Every Privileged Access engagement is fixed-fee with a costed roadmap and named senior identity architect on-record from kickoff through go-live. No T&M overruns, no offshore handoff, no junior-analyst-led Tier 0 cutover.

Compliance-native

EPC Group is compliance-native across HIPAA, SOC 2, FedRAMP, FINRA, CMMC, and GxP. Privileged Access deployments ship with auditor-ready Tier 0/1/2 control matrices, break-glass evidence, and PIM activation logs.

Privileged access mapped to the regulatory reality

Bastion + PIM + JIT controls map directly to control families in NIST CSF 2.0 (Protect, Detect, Respond), ISO 27001 Annex A.9 (Access Control), HIPAA Security Rule §164.308 (Administrative Safeguards), FedRAMP AC and IA families, and CMMC 2.0 AC and IA practices. EPC Group extends the mapping into a documented control matrix that auditors will accept. See the standards alignment library for the full mapping.

HIPAA
SOC 2
FedRAMP
FINRA
CMMC
GxP

Frequently asked questions — Azure Bastion, Entra PIM, and JIT

How does Azure Bastion + Entra PIM compare to CyberArk Privileged Access Manager?

Bastion + PIM and CyberArk PAM are the two leading enterprise privileged access approaches for organizations with significant Azure footprint. Bastion + PIM wins on bundled value (already included or low-incremental cost inside Microsoft 365 E5 and Azure consumption), on native Azure integration (Conditional Access, Defender XDR fusion, Sentinel connectors), and on Bastion Premium session recording with customer-managed keys. CyberArk wins on multi-cloud coverage (AWS, Google Cloud, on-premises in one unified vault), credential vaulting for legacy non-Microsoft systems, and session recording forensics across non-Azure protocols. EPC Group recommends Bastion + PIM as the primary stack for Microsoft-anchored estates, with CyberArk reserved for legacy on-premises and multi-cloud edges.

How does Azure Bastion + Entra PIM compare to BeyondTrust Privileged Remote Access?

BeyondTrust Privileged Remote Access is a strong competitor for third-party vendor access and remote support — the patterns where the privileged user is outside the corporate identity perimeter. BeyondTrust wins on agentless reach into non-Azure infrastructure (network devices, legacy industrial control systems, OT environments) and on the vendor-facing collaboration model. Bastion + PIM wins on Azure-native administrative paths, on the unified Microsoft identity and audit story auditors find easier to evaluate, and on the pricing model at scale. The decision point is the percentage of privileged access that targets Azure-native resources versus legacy infrastructure outside Azure.

How does Azure Bastion + Entra PIM compare to Delinea (formerly Thycotic) Secret Server?

Delinea Secret Server is principally a credential vault and password rotation product; Bastion + PIM is principally an activation-and-session-control architecture for Microsoft cloud. The two solve adjacent problems. Delinea wins on managing the long tail of legacy service-account credentials where automated password rotation is the dominant control. Bastion + PIM wins on the Azure-native administrative path and on eliminating standing administrative grants through eligible-only PIM. Many EPC Group customers run both — Delinea for the legacy service-account vault, Bastion + PIM for the Azure administrative plane — feeding the same SIEM (Microsoft Sentinel) for cross-source correlation.

What does Azure Bastion cost across Basic, Standard, and Premium SKUs?

Azure Bastion is priced on an hourly host charge plus outbound data transfer with three SKU tiers. Basic carries an hourly base for two fixed instance units in a single virtual network — appropriate for development. Standard carries a higher hourly base plus a per-instance hourly charge as you scale from 2 to 50 instance units, plus the native client tunnel and IP-based connection features. Premium adds session recording (with storage account cost falling to the customer), private-only deployment, and graph-based session policy — the SKU EPC Group recommends for HIPAA, FedRAMP, CMMC, FINRA, and GxP estates. Most production architectures use Standard in the hub virtual network with peering reach into spoke workload virtual networks.

What licensing does Entra Privileged Identity Management require?

Entra PIM requires Entra ID P2 licensing, which is included in Microsoft 365 E5, Microsoft 365 E5 Security, and the standalone Entra ID P2 SKU. P2 covers PIM for both Entra ID directory roles and Azure resource roles, plus Identity Protection risk-based Conditional Access that pairs with PIM for the strongest activation posture. Customers on Entra ID P1 cannot activate PIM and must either upgrade to P2 or remain on standing-active assignments — an outcome EPC Group strongly discourages for any tenant with regulated workload. The typical pattern in mixed populations is P2 for administrators and developers and P1 or below for general users, supported through group-based licensing.

What audit trails does Azure Bastion + PIM produce, and which control families do they map to?

Bastion produces Activity Log entries for every connection, disconnection, file-copy event, and session recording (Premium SKU). The recording stores in an Azure Storage account under customer-managed keys with configurable retention. PIM produces audit entries for every eligible assignment, active assignment, activation request, approver action, access review, and auto-removal. Both streams flow into the Entra audit log, Azure Monitor, Microsoft Sentinel, and Defender XDR. The combined audit trail maps to NIST CSF 2.0 Protect.AA and Detect.CM, ISO 27001 Annex A.9, HIPAA §164.308(a)(3) and §164.308(a)(4), FedRAMP AC-2 and AC-5, CMMC 2.0 AC.L2-3.1.1 and AC.L2-3.1.5, and SOC 2 CC6.1 and CC6.3.

How does Defender for Cloud JIT VM access work, and how does it relate to Azure Bastion?

Defender for Cloud Just-in-Time VM access is a complementary control to Azure Bastion. JIT governs the network-layer permission to reach the VM (the NSG rule that allows RDP/SSH on the management port) and gates it behind an approval workflow with automatic close after the requested time window. Bastion governs the connection path itself — the browser or native-client session that reaches the VM. Together they form a two-layer control: JIT decides whether the port is open at all, Bastion decides who reaches it through what session. The EPC Group default deploys Bastion in the hub virtual network as the only administrative path and JIT VM access on the spoke workload subnets so the NSG rule is closed until activation.

What does an Azure Bastion + PIM engagement cost, and how long does the EPC Group Privileged Access Accelerator take?

EPC Group delivers full Bastion + PIM + JIT activation under a fixed-fee engagement between $150,000 and $500,000 depending on Azure subscription count, privileged-user population, regulatory requirements, tiered-admin scope, and managed-service tail. A typical engagement runs eight to fourteen weeks across the five phases. Mid-market engagements (single subscription, small Tier 0, Standard SKU Bastion) cluster near $150K-$250K. Complex engagements (multi-subscription, Premium SKU Bastion with session recording, MSP delegated access, M&A integration in scope) cluster near $400K-$500K. Managed Privileged Access is a separate annual subscription priced per protected administrator with senior-architect escalation included.

Continue exploring the EPC Group enterprise Microsoft library

Bastion + PIM + JIT sits inside the broader Microsoft identity and cloud security story. These hubs cover the adjacent territory.

Eliminate standing administrative access in Azure

Book a Privileged Access briefing with an EPC Group senior identity architect. Two-hour working session — standing-access inventory, Tier 0/1/2 review, Bastion + PIM + JIT accelerator scoping. Zero obligation, board-ready output.

AI assistant — not human