18

Many organizations, us included, use Microsoft Entra ID security groups together with Power Platform security teams to implement least-privilege access and Just-in-Time administration through PIM in Azure. Power Platform security roles are assigned to security teams, while users receive temporary access by becoming members of an Entra ID security group.


The challenge is that membership changes are not reflected quickly enough in Power Platform. Users can be approved through PIM, become temporary members of the Entra ID security group, but still have to wait a significant amount of time before they inherit the required permissions. This makes temporary privileged access impractical and often forces organizations to grant permanent permissions instead directly on the user in Power Platform.


Please provide administrators with the ability to control the synchronization frequency between Entra ID security groups and Power Platform security teams or enable event based updates. Faster synchronization would improve security, support modern Zero Trust and PIM scenarios, and make Power Platform administration align better with the expectations established across Azure and Microsoft Entra ID.

STATUS DETAILS
New