PIM eligible vs active vs permanent, and where scope and activation controls live

Verdict: Use an eligible assignment for privileges held only when activated. Narrow reach with assignment scope, not duration. Justification and MFA are activation role settings. Conditional Access gates sign-in, never whether a role is standing.

CriterionEligible assignmentActive assignmentPermanent activeEntra custom roleConditional Access
What it grantsPrivileges only after a time-bound activationStanding access for the whole durationContinuous access, no activation stepA tailored directory permission setSign-in conditions, not permissions
FitsMonth-end or incident roles that must not sit dormantA defined active window with no per-use stepNever for least privilegePassword reset plus license management with no matching built-in roleMFA or device compliance at sign-in
Narrowed byActivation window and approvalDurationNothingOnly the permissions selectedTargeted app or user

Rules

Traps