diff --git a/docs/id-governance/privileged-identity-management/concept-pim-for-groups.md b/docs/id-governance/privileged-identity-management/concept-pim-for-groups.md index 51d07b780e2..923515ff47f 100644 --- a/docs/id-governance/privileged-identity-management/concept-pim-for-groups.md +++ b/docs/id-governance/privileged-identity-management/concept-pim-for-groups.md @@ -44,6 +44,9 @@ To learn more about Microsoft Entra built-in roles and their permissions, see [M Microsoft Entra role-assignable group feature is not part of Microsoft Entra Privileged Identity Management (Microsoft Entra PIM). For more information on licensing, see [Microsoft Entra ID Governance licensing fundamentals](~/id-governance/licensing-fundamentals.md) . +>[!IMPORTANT] +>Guest accounts with "Guest users have the same access as members (most inclusive)" permissions that are owners of a PIM-enabled group will have the same access as regular owners. However, Limited and Restricted Guest Users will experience limited access when accessing the "Privileged Identity Management" activities in a group. They will not be able to see if the group is already enabled for PIM, and instead, they will see a prompt asking, "Enable PIM for this group?" Additionally, restricted guest accounts will not have visibility into activated roles for other users. + ## Relationship between role-assignable groups and PIM for Groups @@ -104,4 +107,4 @@ Provisioning configuration depends on the application. Generally, we recommend h - [Bring groups into Privileged Identity Management](groups-discover-groups.md) - [Assign eligibility for a group in Privileged Identity Management](groups-assign-member-owner.md) - [Activate your group membership or ownership in Privileged Identity Management](groups-activate-roles.md) -- [Approve activation requests for group members and owners](groups-approval-workflow.md) \ No newline at end of file +- [Approve activation requests for group members and owners](groups-approval-workflow.md)