When searching for the configuration of Privileged Identity Management for role Partner Tier2 Support , administrators often realize the role does not natively appear in the entra.microsoft.com/view/MicrosoftAzurePIMCommon blade. This intent falls under troubleshooting and service operation
Understanding the Missing Role in Microsoft Entra
The core reason is that this specific support role is a delegated privilege tied exclusively to the Microsoft Partner Center (via Granular Delegated Admin Privileges, or GDAP), rather than a standard Entra ID built-in directory role like Global Administrator. To apply PIM to this role, organizations must utilize PIM for Groups . By creating an Entra security group, enabling PIM governance on it, and subsequently mapping that group to the support role in Partner Center, administrators achieve the desired just-in-time access
Step-by-Step Solution for PIM Configuration
Follow these Microsoft Entra actions for Activate the Partner Tier 2 Support Role with Microsoft Entra PIM in order. The key interface checkpoint is Identity Governance > Privileged Identity Management > Groups.

- Navigate to the Microsoft Entra admin center ( entra.microsoft.com ) and log in with Privileged Role Administrator credentials
- Go to Identity > Groups > All groups and click New group . Create a Security group named "PIMPartnerTier2" and save it
- Navigate to Identity Governance > Privileged Identity Management > Groups
- Click Discover groups , search for "PIMPartnerTier2", select the checkbox, and click Manage group to bring it under PIM control
- Inside the newly managed group's PIM menu, click Assignments > Add assignments . Select your tier 2 support IT staff and assign them as Eligible members
- Log into the Microsoft Partner Center dashboard, navigate to Customers > Administer > GDAP relationship requests
- Map the PIM-enabled Entra ID group ("PIMPartnerTier2") to the actual support role for your client tenants. Expected result: Support agents must now actively elevate their group membership in Entra PIM before they can execute tier 2 support actions
How to Verify the Microsoft Entra Result
Validate the change before closing the app: Map the PIM-enabled Entra ID group ("PIMPartnerTier2") to the actual support role for your client tenants. Expected result: Support agents must now actively elevate their group membership in Entra PIM before they can execute tier 2 support actions A different result usually means the wrong file, account, or Microsoft Entra admin center was used.
WPS Office: A Free Microsoft Office Alternative for Activate the Partner Tier 2 Support Role with
For local work related to Activate the Partner Tier 2 Support Role with Microsoft Entra PIM, WPS Office is a free Microsoft Office-compatible alternative. It does not reproduce every proprietary Microsoft Entra service or administrator control, so use the Microsoft steps above when the task depends on that specific platform.
While you complete “Activate the Partner Tier 2 Support Role with Microsoft Entra PIM” in Microsoft’s interface, use WPS Writer, Spreadsheets, and PDF for local policy notes, user lists, audit exports, and PDF records; WPS AI can also summarize administrative notes and organize exported data. Because the desktop interface follows familiar document, spreadsheet, presentation, and PDF conventions, most users can move common local work without rebuilding their workflow.

Microsoft Entra FAQs About Activate the Partner Tier 2 Support Role with Microsoft Entra PIM
Why can't I see the partner support role in Azure AD PIM directly?
This specific support role is a Microsoft Partner Center delegated privilege, not a standard Entra ID directory role. It will never natively populate in the Azure AD roles blade. You must use PIM for Groups to secure it.
Do I need a specific Entra ID license to manage this setup?
Yes. To utilize Privileged Identity Management for Groups—which is mandatory to secure GDAP roles using this method—your partner tenant must have Entra ID P2 (formerly Azure AD Premium P2) licenses assigned to the administrators utilizing the elevation feature.
How do I verify my support access is active after PIM elevation?
After elevating your eligible group membership in Entra PIM, wait a few minutes, then navigate to the Microsoft Partner Center. Open a client tenant's service management portal; you should now possess the necessary permissions to administer services and troubleshoot issues.
What happens to active client support sessions when my PIM elevation expires?
Once the time-bound PIM elevation expires (e.g., after 4 hours), your Entra ID token will instantly lose the group membership. Active administrative sessions in the Partner Center or client admin centers will begin denying write actions, prompting an access error. You will need to re-elevate in PIM to resume configuration.




