Activate a PIM-eligible Azure role as part of your identity chain
More and more Azure resource roles are handed out as PIM-eligible rather than standing: you hold
the role only after you activate it, for a time-boxed window, with a justification. That activation
is a multi-step REST dance against Azure Resource Manager - enumerate what you are eligible for,
file a self-activation request, then poll until it provisions - and there is no native az command
for activating an eligible Azure resource role. So every working session starts with hand-rolled
az rest calls or a third-party script before you can actually run anything.


