---
title: Automate Microsoft Entra PIM with Sheriff - Frontier
description: Sheriff enables you to automate the configuration and operation of Microsoft Entra Privileged Identity Management (PIM) to secure your Azure estate.
image: https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/social-sheriff-featured.png
---

[![Frontier logo with white text](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/frontier-logo-horizontal-white.svg)](https://frontierhq.com)

- [KUBERNETES](https://frontierhq.com/kubernetes)
- [DATA & AI](https://frontierhq.com/data-ai)
- [CLOUD](https://frontierhq.com/cloud)
- [AUTOMATION](https://frontierhq.com/automation)
- [PRODUCTS](https://frontierhq.com/products)
- ABOUT US
  
    - [PARTNERS](https://frontierhq.com/partners)
    - [WHO WE ARE](https://frontierhq.com/who-we-are)
    - [THOUGHT LEADERSHIP](https://frontierhq.com/blog)

[Let's Chat](https://frontierhq.com/lets-chat)

 Innovate safely

# Sheriff

## Automate Microsoft Entra PIM to secure your enterprise

Sheriff enables you to automate the configuration and operation of Microsoft Entra Privileged Identity Management (PIM) across your enterprise, secure by default thanks to some clever features Sheriff adds.

[GET STARTED](https://frontierhq.com/products/sheriff#get-started) [LEARN MORE](https://frontierhq.com/products/sheriff#benefits)

![Sheriff logo](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/sheriff-logo-without-border.svg)

 Sheriff

## Benefits

#### Single source of truth

Maintain a single source of truth for access config across your entire Azure estate.

#### Detect and correct misconfigurations

Stateless operation means Sheriff will detect and correct misconfigurations automatically.

#### Operate secure by default

Clever features in Sheriff, like role management policy inheritance and defaults, enable you to operate secure by default.

#### Reduce operating costs

Operate at reduced cost by using Sheriff to automate time-intensive manual management.

Automated

### Sheriff is made to run in CI

Sheriff is primarily a command-line (CLI) tool, made to run on any modern CI system, including Azure DevOps, Jenkins, GitHub Actions, GitLab CI/CD, Bamboo, CircleCI, Travis CI, TeamCity and Octopus Deploy. If you're using Sheriff on Azure DevOps, the [Sheriff extension](https://marketplace.visualstudio.com/items?itemName=gofrontier.Sheriff) makes it even easier. Of course, you can run it locally, too, which is handy for using *import* or *plan*.

![CI/CD logo](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/cicd-log.svg)

 Sheriff

## Features

#### Active and eligible assignments

Manage active and eligible role assignments for users and groups, including start and end dates, at any scope.

#### Role management policies

Manage role management policies to require approval to activate privileged roles, enforce multifactor authentication and more.

#### Policy inheritance and defaults

Overcome limitations in Microsoft Entra PIM with Sheriff’s role management policy inheritance and defaults.

#### Import existing config

Import your existing config to immediately establish a single source of truth.

Accredited

### Sheriff has been created by Microsoft Azure experts

We are a platform engineering company. Our directors have been building in Microsoft Azure since 2012. We're also a Microsoft Solutions Partner. Sheriff was born from the work we do with our customers to enable them to operate predictably and innovate safely.

![Microsoft Solutions Partner logo](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/SolutionsPartner-png-1.png)

 Sheriff manages

## Azure resource roles

![azure-resources](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/azure-resources.svg)Sheriff manages **active** and **eligible** role assignments for built-in Azure resource roles like **Reader**, **Contributor** and **Owner**.

And it’ll manage custom roles, too. You can have up to 5,000 of those per tenant.

Use Sheriff to manage assignments and role management policies for **users** and **groups** at **subscription**, **resource group** and **resource** scopes.

See [Assign Azure resource roles in Privileged Identity Management](https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-resource-roles-assign-roles) for more information.

 Code example

```
# config/groups/CSG-RBAC-Engineers.yml
---
subscription:
  active:
    - roleName: Reader
  eligible:
    - roleName: Contributor
    
resourceGroups:
  storageaccount-rg:
    eligible:
      - roleName: Storage Blob Data Reader
        endDateTime: 2024-11-30T18:00:00
```

Trusted

### FTSE 100 companies use Sheriff

A financial services company uses Sheriff to configure and operate Microsoft Entra PIM for Azure resource roles, Microsoft Entra roles and Groups across multiple business units. It allows them to use Git as their single source of truth for access configuration across Azure and beyond, combining the benefits of an as-code approach with a single unified configuration model that's easy to understand and maintain.

![sheriff-logo-without-border](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/sheriff-logo-without-border.svg)

 Sheriff manages

## Microsoft Entra roles

![entra-logo](https://22238495.fs1.hubspotusercontent-na1.net/hub/22238495/hubfs/entra-logo.webp?width=150&height=133&name=entra-logo.webp)Sheriff manages **active** and **eligible** role assignments for built-in Microsoft Entra roles like **Application Developer**, **Security Operator** and **Global Administrator**.

And it’ll managecustom roles, too. You can have up to 5,000 of those per tenant.

Use Sheriff to manage assignments and role management policies for **users** and **groups** at **directory**, **administrative unit**, **application** and **service principal** scopes.

See [Assign Microsoft Entra roles in Privileged Identity Management](https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-add-role-to-user) for more information.

 Code example

```
# config/users/sally@frontierhq.com
---
directory:
  eligible:
    - roleName: Global Administrator
    
applications:
  14739921-46fd-4faf-9d77-caaaf19fbda8: # SonarQube
    active:
      - roleName: Application Developer
    eligible:
      - roleName: Application Administrator
      
administrativeUnits:
  2a3c3347-e294-4350-aec5-6cab3323599c: # Engineering
    eligible:
      - roleName: Helpdesk Administrator
```

Cross-platform

### Run Sheriff on any platform

Sheriff runs on Windows, Linux and MacOS. If you're using Sheriff on Azure DevOps, the [Sheriff extension](https://marketplace.visualstudio.com/items?itemName=gofrontier.Sheriff) makes it even easier to install and run Sheriff.

 Sheriff manages

## Groups (PIM-enabled)

![azure-groups](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/azure-groups.svg)Sheriff manages **active** and **eligible** role assignments for PIM-managed group roles like **Member** and **Owner**.

Use Sheriff to manage assignments and role management policies for **users** and **groups** for PIM-enabled groups.

See [Assign eligibility for a group in Privileged Identity Management](https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/groups-assign-member-owner) for more information.

 Code example

```
# config/groups/CSG-RBAC-SRE.yml
---
managedGroups:
  CSG-App-OpenShiftUser:
    active:
      - roleName: Member
      
  CSG-App-OpenShiftClusterAdmin:
    eligible:
      - roleName: Member
      
  CSG-App-SonarQubeAdmin:
    eligible:
      - roleName: Member
      - roleName: Owner
```

EBOOK

### Sheriff makes PIM even better

Get our free ebook on how you can level up your B2B SaaS content marketing

![pim](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/pim.png)

 Sheriff manages

## Role management policies

![azure-backlog](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/azure-backlog.svg)Sheriff manages **activation**, **assignment** and **notification** role management policy rules for complete governance coverage.

These rules cover things like whether **multi-factor authentication** (MFA) is required to activate an eligible role or group membership; who receives **alerts** when a role is activated; or whether you can create **permanent** role assignments, group ownership, or group memberships.

Sheriff extends out-the-box PIM role management policy features to make it safer and easier to operate at scale, such as **policy inheritance and defaults**. These allow for the creation **global or role specific defaults**, reducing the management overhead of PIM and establishing a **secure by default** operating model.

Use Sheriff to manage role management policy rules for **Azure resource** roles, **Microsoft Entra** roles and **Groups** (PIM-enabled).

See [Start using Privileged Identity Management](https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-getting-started) for more information.

 Code example

```
# config/policies/Contributor.yml
---
default:
  - rulesetName: StandardRules
resourceGroups:
  storageaccount-rg:
    - rulesetName: RelaxedRules
```

```
# config/policies/rulesets/StandardRules.yml
---
rules:
  - id: Expiration_EndUser_Assignment
    patch:
      maximumDuration: PT1H
  - id: Enablement_EndUser_Assignment
    patch:
      enabledRules:
        - Justification
        - MultiFactorAuthentication
        - Ticketing
```

```
# config/policies/rulesets/RelaxedRules.yml
---
rules:
  - id: Expiration_EndUser_Assignment
    patch:
      maximumDuration: PT4H
  - id: Enablement_EndUser_Assignment
    patch:
      enabledRules:
        - MultiFactorAuthentication
```

 Sheriff

## FAQs

### Where does Sheriff run?

Sheriff is primarily a command-line (CLI) tool that can be run on Windows, Linux and MacOS. It's been made to run on any modern CI system, including Azure DevOps, Jenkins, GitHub Actions, GitLab CI/CD, Bamboo, CircleCI, Travis CI, TeamCity and Octopus Deploy. If you're using Sheriff on Azure DevOps, the [Sheriff extension](https://marketplace.visualstudio.com/items?itemName=gofrontier.Sheriff) makes it even easier. Of course, you can run it locally, too, which is handy for using *import* or *plan*.

### How does Sheriff authenticate?

Sheriff uses the [Azure Identity module for Go](https://learn.microsoft.com/en-us/azure/developer/go/azure-sdk-authentication) to authenticate to Azure and Microsoft Entra. Azure Identity allows for a number of different authentication mechanisms to be used, including environment variables, managed identity, workload identity and Azure CLI authentication.

See [Azure Identity module for Go](https://learn.microsoft.com/en-us/azure/developer/go/azure-sdk-authentication) for more information.

### What Microsoft licenses are required?

You need either Microsoft Entra ID Governance licenses or Microsoft Entra ID P2 licenses to use PIM - and therefore Sheriff - and all of its settings.

See [Microsoft Entra ID Governance licensing fundamentals](https://learn.microsoft.com/en-us/entra/id-governance/licensing-fundamentals#privileged-identity-management) for more information.

### What happens if someone changes PIM config outside of Sheriff?

Sheriff is stateless, which means it compares roles assignments in Azure and Microsoft Entra with what's been defined in configuration every time it runs. This means when it finds something either not in or different to that configuration - known as configuration drift - it corrects it. Detecting and correcting misconfigurations like this is one of Sheriff's most valuable features.

### Can I exclude certain users or groups from being managed by Sheriff?

Yes, Sheriff includes support for excluding specific users or groups from being managed by Sheriff, which can be useful for example when service accounts that have role assignments managed elsewhere are present in the subscriptions and tenants where Sheriff is being used.

 Sheriff

## Pricing

#### Azure resource roles

## £950/year

per subscription

Only charged for first 20 subscriptions

---

- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Azure resource roles
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Role management policies
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Policy inheritance and defaults
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Free upgrades
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Business hours support

[GET STARTED](https://frontierhq.com/products/sheriff#get-started)

#### Microsoft Entra roles + Groups

## £2,950/year

for first tenant

## £950/year

for additional tenants

Only charged for first 3 tenants

---

- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Microsoft Entra roles
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Groups (PIM-enabled)
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Role management policies
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Policy inheritance and defaults
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Free upgrades
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Business hours support

[GET STARTED](https://frontierhq.com/products/sheriff#get-started)

#### Unlimited

## £24,950/year

Flat fee for Azure resource roles, Microsoft Entra roles and Groups across unlimited subscriptions and tenants.

---

- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Azure resource roles
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Microsoft Entra roles
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Groups (PIM-enabled)
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Role management policies
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Policy inheritance and defaults
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Free upgrades
- ![Checkmark](https://f.hubspotusercontent30.net/hubfs/8823337/Checkmark.svg) Business hours support

[GET STARTED](https://frontierhq.com/products/sheriff#get-started)

 Sheriff

## Get started with a free trial

Fill in your details below and we'll get in touch with all the details you need to start securing your enterprise with Sheriff.

 Frontier

## Find out more

<https://frontierhq.com/products>

Products

#### Automate and simplify

Sometimes there is a right answer. Our products automate and simplify the building blocks you just need to get right.

[View products](https://frontierhq.com/products)

<https://frontierhq.com/blog>

Solutions

#### Enable and accelerate

Standard solutions, advanced engineering. We deploy industry recognised solutions that enable and accelerate.

[View solutions](https://frontierhq.com/solutions)

<https://frontierhq.com/who-we-are>

Who we are

#### A platform engineering company

We enable organisations to operate predictably and innovate safely by providing technology assurance, automated.

[Learn more](https://frontierhq.com/who-we-are)

## Operate predictably. Innovate safely.

[LET'S CHAT](https://frontierhq.com/lets-chat)

[![Frontier logo with white text](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/frontier-logo-horizontal-white.svg)](https://frontierhq.com)

Centrum House  
38 Queen Street  
Glasgow G1 3DX

### Products

- [Sheriff](https://frontierhq.com/products/sheriff)
- [Governor](https://frontierhq.com/products)
- [Wrangler](https://frontierhq.com/products)
- [Ranger](https://frontierhq.com/products)

### Solutions

- [Cloud landing zones](https://frontierhq.com/solutions)
- [Container platforms](https://frontierhq.com/solutions)
- [Deployment automation](https://frontierhq.com/solutions)
- [Security automation](https://frontierhq.com/solutions)

### Company

- [Who we are](https://frontierhq.com/who-we-are)
- [Thought leadership](https://frontierhq.com/blog)
- [Contact us](https://frontierhq.com/lets-chat)
- [Terms](https://frontierhq.com/terms-and-conditions)

![Microsoft Partner logo](https://22238495.fs1.hubspotusercontent-na1.net/hub/22238495/hubfs/SolutionsPartner-png-1.png?width=163&height=100&name=SolutionsPartner-png-1.png) ![Kubernetes Certified Service Provider logo](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/kubernetes-kcsp-color-1.svg) ![Elastic Partner logo](https://22238495.fs1.hubspotusercontent-na1.net/hub/22238495/hubfs/partner-badge.png?width=100&height=100&name=partner-badge.png)![SUSE Emerald Partner logo](https://22238495.fs1.hubspotusercontent-na1.net/hub/22238495/hubfs/Sell%20Emerald%20Partner.png?width=100&height=100&name=Sell%20Emerald%20Partner.png)![Cyber Essentials logo](https://22238495.fs1.hubspotusercontent-na1.net/hub/22238495/hubfs/Cyber-Essentials-Logo-v2.png?width=84&height=100&name=Cyber-Essentials-Logo-v2.png) ![Living Wage Employer logo](https://22238495.fs1.hubspotusercontent-na1.net/hub/22238495/hubfs/living-wage-employer-logo.png?width=127&height=100&name=living-wage-employer-logo.png) ![Great Place To Work logo](https://22238495.fs1.hubspotusercontent-na1.net/hubfs/22238495/great-place-to-work-logo.svg)

© 2026 Frontier