Privileged Entra ID Role Assignment Outside PIM (T1098.003)

This rule detects when sensitive administrative roles are assigned directly to users in Microsoft Entra ID (formerly Azure AD) without utilizing the Privileged Identity Management (PIM) service. Direct assignment of these roles bypasses the security controls and JIT (Just-In-Time) access workflows enforced by PIM, potentially indicating unauthorized privilege escalation or a misconfiguration.