PIM-eligible administrators should not fail the "Restrict Azure Portal Management" control
J
John Granade
The control currently treats any Conditional Access exclusion as non-compliant. However, exclusions for Privileged Identity Management (PIM) eligible administrators are required for PIM to function correctly.
Conditional Access evaluates active role assignments, not eligible assignments. An administrator with an eligible role is treated as a standard user until they activate the role through PIM. If the Azure Portal and Entra Admin Center are blocked, those users cannot access the location where elevation occurs, creating a catch-22 where they cannot elevate because they are not already elevated.
Consider allowing exclusions for PIM-eligible administrator groups without marking the control as non-compliant.