
Explanation:
You should use the Privileged Identity Management (PIM) Administrator role to determine the users and roles to be managed using PIM. The PIM Administrator will be the person performing the initial setup of PIM and will therefore need to collect the requirements for the implementation.
You should use the PIM Administrator role to assign users as eligible admins. The PIM Administrator will determine and configure which users will have which rights within the environment. As this is an administrative task, the PIM Administrator role will be required for this.
You should use the PIM User role to request the activation of eligible admin roles. When users require elevated rights for their account, they can create a PIM activation request to be granted the requested permissions.
You should use the PIM Approver role to view and approve activation requests. When PIM requests are created, the PIM Approver will approve or deny the request for the elevated permissions.
You should use the PIM Administrator role to view and export a history of assignments and activations. The PIM Administrator can access the history to make sure compliance requirements are met.