Skip to main content

Legora Lockbox / PIM

Version 1.2, 8 July 2025

Maja Lehbert avatar
Written by Maja Lehbert
Updated this week

Introduction

This document provides a technical overview of Legora’s implementation of Azure Privileged Identity Management (PIM) within the context of customer data environments. It outlines how Legora engineers obtain and use elevated privileges in a controlled, auditable, and customer-approved manner.

PIM forms part of Legora’s Lockbox security framework, ensuring that no engineer has standing access to customer systems. All access is time-bound, explicitly approved by the customer, and fully logged in Azure Audit Logs, which are surfaced through Legora’s governance interface for transparency and compliance.

This process reinforces Legora’s commitment to security, accountability, and customer control, ensuring that privileged operations such as maintenance, performance troubleshooting, or configuration changes are performed with minimal risk and complete traceability.

Access Workflow

  1. Request Access

If a Legora engineer needs to perform maintenance (e.g., upgrade database size, troubleshoot performance), they must request access via Azure PIM. The request includes:

  • The role/privilege being requested

  • A motivation/explanation for the access

  • Date and duration for the elevation

2. Customer Approval

  • A designated approver list (defined by the customer) receives the request.

  • An approver must explicitly approve the request before any access is granted.

3. Time-Bound Access

  • Once approved, the engineer receives temporary access for a limited duration.

  • Access automatically expires after the set time period, ensuring no lingering privileges.

4. Auditing & Logging

  • All operations are logged in Azure Audit Logs.

  • These logs are automatically integrated into the Legora user interface, allowing users with the auditor role to review:

    • Who requested access

    • Who approved it

    • What operations were performed

    • When access started and ended

Frequently Asked Questions

Q: What is Azure Privileged Identity Management (PIM)?

A: Azure PIM is a service that helps organizations manage, control, and monitor access to important resources in Azure. It ensures that privileged roles are only activated when needed, reducing the risk of excessive or unauthorized access.

Q: Why does Legora use Azure PIM?

A: Legora uses PIM as part of its Lockbox security framework to ensure engineers never have permanent (“standing”) access to customer systems. All access is temporary, customer-approved, and auditable, reinforcing Legora’s commitment to security, accountability, and transparency.

Q: Who approves access requests?

A: Each customer maintains a designated approver list. Access is granted only after an authorized approver explicitly approves the request. This ensures customers retain full control over who can access their environment.

Q: How long does access last?

A: Access is strictly time-bound. Once approved, it automatically expires after the approved duration, ensuring no lingering or unintended privileges remain active.

Did this answer your question?