Assign Azure resource roles in Privileged Identity Management
In brief
The documentation now explains that `duration: P365D` makes an eligible assignment expire after 365 days. Permanent eligibility requires the target scope’s role management policy to allow it.
What Entra admins need to know
Administrators should verify the duration and policy settings when creating eligible assignments.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
}
### Response
Status code: 201
Response
Status code: 201
@@ -2,7 +2,7 @@ title: Assign Azure resource roles in Privileged Identity Management description: Learn how to assign Azure resource roles in Privileged Identity Management (PIM). ms.topic: how-to-ms.date: 04/23/2026+ms.date: 08/06/2026 ms.custom: sfi-ga-nochange, sfi-image-nochange #Customer Intent: As an Azure resource administrator, I want to assign Azure resource roles using PIM to provide just-in-time access to subscriptions, resource groups, and other Azure resources. ---@@ -127,6 +127,9 @@ PUT https://management.azure.com/providers/Microsoft.Subscription/subscriptions/ } ```` +> [!NOTE]+> The `duration` field (value `P365D` in this example) sets the eligible assignment to expire after 365 days. To create permanent eligibility, configure the role management policy at the target scope to allow it.+ ### Response Status code: 201 