Skip to content

Suggested extension #14

@jeremyhagan

Description

@jeremyhagan

I was thinking something along the lines of this script, so I may just adapt this one, however my suggested mode of operation is as follows:

  1. Admin is logged into jump host and uses PowerShell to activate PIM group
  2. Script polls the activation request until it is successful (need to think up a way to backgrounding this for PIM requests which require approval)
  3. Once PIM is successful, script activates the write back script running as an automation runbook via a webhook, supplying the PIM group name. Write back script is running on a hybrid worker. Use time base group membership feature so that the removal is not reliant on the script running.
  4. Elevation script then polls the desired on-prem group until membership is active
  5. Once elevation is complete, Elevation script purges the logged in user's Kerberos token so that the elevated access is available immediately.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions