Admin consent
TeamsPIM reads and acts on privileged access data through Microsoft Graph. Several of the permissions it needs can only be granted by an administrator on behalf of the whole organisation, so a tenant-wide admin consent is required before anyone in your tenant can use TeamsPIM, including the Customer Admin Portal.
Who can grant it
Section titled “Who can grant it”TeamsPIM asks for a Global Administrator of your tenant: “A Global Administrator of your tenant has to grant admin consent”. If you are not one, copy the consent link and send it to someone who is. Consent must be granted in the same tenant as the purchase.
Microsoft describes tenant-wide consent in Grant tenant-wide admin consent to an application. Review the permissions before you accept; they are listed in the permissions reference.
Where to start it
Section titled “Where to start it”You can start consent from three places. They all lead to the same Microsoft consent page for the TeamsPIM application.
1. The activation drawer on the landing page
Section titled “1. The activation drawer on the landing page”During activation, the “Subscription Activation Request” drawer contains an Admin consent link. When consent finishes, the drawer shows “Admin consent verified.” and Submit becomes available. If it shows “Admin consent not verified yet. Complete consent and try again.”, finish consent in the tab that opened and try again.
2. The banner in the Customer Admin Portal
Section titled “2. The banner in the Customer Admin Portal”If consent is missing, the Customer Admin Portal shows a banner: “TeamsPIM has not been approved for your organisation yet.” It offers two buttons:
- Grant admin consent opens the consent page, for when you are a Global Administrator.
- Copy link copies the consent link (“Copy the link to send to a Global Administrator”).
If sign-in to the portal itself fails with “Your organisation hasn’t approved TeamsPIM yet.”, the same applies: a Global Administrator grants consent, then you sign in again.
3. The Add a tenant dialog
Section titled “3. The Add a tenant dialog”When you add another directory to a subscription, the “Add a tenant” dialog asks for consent in that tenant: “A Global Administrator of this tenant must grant TeamsPIM admin consent before it can be added.” Use Open consent or Copy link, then Verify.
- Open the consent page, or send the link to a Global Administrator.
- The Global Administrator signs in, reviews the permissions and accepts.
- Return to TeamsPIM and verify, or reload the page.
Two app registrations
Section titled “Two app registrations”TeamsPIM uses two Microsoft Entra app registrations. The consent described on this page is for the first, TeamsPIM.
| Registration | What it asks for |
|---|---|
| TeamsPIM (the app in Teams and its back end) | Microsoft Graph delegated and application permissions for PIM, plus delegated Azure Service Management access |
| TeamsPIM Customer Admin Portal | Delegated permissions only: Microsoft Graph Group.Read.All, GroupMember.Read.All, User.Read and User.ReadBasic.All, and Azure Service Management user_impersonation |
The Customer Admin Portal reads your directory through the TeamsPIM application’s permissions. That is why TeamsPIM consent has to be in place before the portal can list your users and groups.
See the permissions reference for every permission and why it is needed.