API · SDK · runtime · authentication lifecycle intelligence

Last updated · 2 October 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-261 · Authentication & identity

Microsoft Entra PIM Iteration 2 beta endpoints stop returning data

Microsoft will stop returning data from the deprecated /beta/privilegedAccess aadRoles and azureResources endpoints on 28 October 2026.

Microsoft EntraPIMprivilegedAccessMicrosoft GraphAPI retirement

Previous state

Integrations could still receive data from the deprecated Iteration 2 /beta/privilegedAccess aadRoles and azureResources endpoints.

Current state

From 28 October 2026 the named endpoints stop returning data; Microsoft directs role and group workflows to current Microsoft Graph APIs and Azure-resource workflows to Azure Resource Manager APIs.

Who needs to care

PIM integrations using /beta/privilegedAccess/aadRoles or /beta/privilegedAccess/azureResources.

What to do

Migrate to the documented Microsoft Graph or Azure Resource Manager replacement APIs before 28 October 2026.

What the source does not prove

Only the named Iteration 2 beta endpoint families are covered; this does not retire every PIM API.

Lifecycle history

Dated event sequence

  1. Retirement guidance published

    Microsoft documented the Iteration 2 replacement paths and cutoff.

  2. Data-return cutoff

    The deprecated endpoints stop returning data.

Evidence ledger

First-party sources

  1. 01
    Microsoft Learn — Microsoft Entra PIM APIs

    Official Microsoft Entra API lifecycle authority · 2026-04-23

    Open official source ↗