Azure PIM Assignment Duration

Hi all,

I’m currently setting up Azure PIM Provisioning via SailPoint, however I’ve run into an issue. I am able to provision both active and eligible roles, but the end time is defaulting to 1 year. I understand from the documentation you can use a before provisioning rule to set an end date, however I would like to set no end date (Permanent assignment) and I’m not sure how to do this. The documentation states you need to provide an end date in ISO_8601 format, but there doesn’t appear to be a way of setting the end date as “Permanent” using this format.

Hi  @lukelav ,

We have “permanent” as acceptable value for the argument duration from 8.3p4 version of IIQ.

If someone has answered your question, please accept their reply as a solution. You can also show your appreciation by giving kudos to helpful replies. Read the Compass How-to tutorials for more information about the community.

Hi  @FlorenceFred  , yes we’re on 8.3p3 at the moment, looking to upgrade soon thankfully!

Did you achieve this via a Before Provisioning rule using:
attributeRequest.put(“duration”, “permanent”);

For anyone else stumbling across this post…

This is available in 8.3p4.

Create a before provisioning rule with the following:

List accounts=plan.getAccountRequests();
  for(AccountRequest accountReq:accounts)
  {
    if(accountReq.getApplication().toString().equalsIgnoreCase("Azure App Name"))
    {
      List attributeRequests=accountReq.getAttributeRequests();
      if(attributeRequests != null){
        for(AttributeRequest attributeRequest:attributeRequests)
        {
          if(attributeRequest.getName().toString().equalsIgnoreCase("azureADEligibleRoles") || attributeRequest.getName().toString().equalsIgnoreCase("azureADActiveRoles"))
          {
            if(attributeRequest.getOperation().toString().equalsIgnoreCase("Add"))
            {
              attributeRequest.put("duration", "permanent");
            }
          }
        }
      }
    }		
  }

Set this rule within the Application > Rules > Before Provisioning Rule

Beware not to forget the necessary imports before this code.

import sailpoint.object.ProvisioningPlan.AttributeRequest;
import sailpoint.object.ProvisioningPlan.AccountRequest;