Privileged Access Management
Source code & Installation
The source code of this kit module can be found here
Run the following command to install the kit module:
collie kit import azure/pam
This kit provides a basic terraform-based approach for managing privileged roles used to administrate your landing zones.
This is a good solution for cloud foundation teams that start in greenfield Azure environments and without a strong backing of established enterprise IAM integration into Entra ID (Azure AD).
For production use, cloud foundation teams should strongly consider implementing group membership management using existing Enterprise IAM processes as well as leveraging Entra ID PIM and Conditional Access features to increase security.
This module is meant to be used with modules like
azure/logging that implement important administrative capabilities and also introduce relevant security groups for manging these capabilities.
|pam_group_members||Optional: manage members for cloud foundation PAM groups via terraform|
|pam_group_object_ids||the object_ids of PAM groups used by the cloud foundation||n/a||yes|