Permissions reference
This page lists the permissions of the TeamsPIM application, the one a Global Administrator consents to (see Admin consent), and of the TeamsPIM Customer Admin Portal. Microsoft describes each Graph permission in the Microsoft Graph permissions reference.
TeamsPIM works in two ways:
- As the signed-in user (delegated). Requesting, activating, deactivating and cancelling activations, and approving or denying requests, run with the user’s own identity. Microsoft Entra and PIM record the user as the actor.
- As the app (application). Reading role settings and audit logs, resolving users and groups, monitoring requests and sending notifications run as the TeamsPIM application.
TeamsPIM: delegated Microsoft Graph permissions
Section titled “TeamsPIM: delegated Microsoft Graph permissions”| Permission | Why |
|---|---|
openid, profile, email, User.Read |
Sign-in |
RoleManagement.ReadWrite.Directory |
Request, activate, deactivate and cancel Microsoft Entra role activations as the user |
PrivilegedAccess.ReadWrite.AzureAD |
PIM for Microsoft Entra roles |
PrivilegedAccess.ReadWrite.AzureADGroup |
PIM for Groups requests as the user |
PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup |
PIM for Groups requests as the user |
TeamsPIM: application Microsoft Graph permissions
Section titled “TeamsPIM: application Microsoft Graph permissions”| Permission | Why |
|---|---|
User.Read.All |
Resolve requestors and approvers |
GroupMember.Read.All |
Resolve approver groups and their members |
Application.Read.All |
Service principal lookups |
AuditLog.Read.All |
Request history, most frequent requests and PIM reports |
RoleManagement.Read.Directory |
Role definitions and schedules, for reports |
RoleManagementPolicy.Read.Directory |
Read role settings: approvers and activation requirements |
RoleManagementPolicy.Read.AzureADGroup |
Read role settings for PIM for Groups |
RoleAssignmentSchedule.ReadWrite.Directory |
Microsoft Entra role requests processed by the bot |
PrivilegedAssignmentSchedule.Read.AzureADGroup |
Monitor PIM for Groups requests |
PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup |
Process PIM for Groups requests |
PrivilegedAccess.Read.AzureAD |
Monitor PIM requests |
TeamsActivity.Send |
Send Teams activity feed notifications |
TeamsAppInstallation.ReadForUser.All |
Check whether the TeamsPIM app is installed for a user |
TeamsAppInstallation.ReadWriteSelfForUser.All |
Install TeamsPIM for users when they are given a licence |
AppCatalog.Read.All |
Find TeamsPIM in your organisation’s Teams app catalogue |
TeamsPIM: other permissions
Section titled “TeamsPIM: other permissions”| Permission | Why |
|---|---|
Azure Service Management user_impersonation (delegated) |
Azure resource role requests run with the user’s own Azure identity |
| Teams single sign-on | TeamsPIM signs users in silently inside Teams |
No Teams resource-specific consent (RSC) permissions. TeamsPIM is a personal app only: a bot chat and tabs for each user, with no team or channel tabs and no message extensions.
Approvals
Section titled “Approvals”Approving or denying on a card signs the approver in, so the decision is made with the approver’s own identity and PIM records them as the reviewer. See Approve or deny a request.
Azure: RBAC Administrator, only where you assign it
Section titled “Azure: RBAC Administrator, only where you assign it”TeamsPIM holds no Azure role by default. When someone with Owner or User Access Administrator selects Assign on the Azure Resources page, TeamsPIM receives the built-in Role Based Access Control Administrator role on that Azure subscription. Unassign removes it.
TeamsPIM Customer Admin Portal permissions
Section titled “TeamsPIM Customer Admin Portal permissions”The portal’s own registration has delegated permissions only, so it acts as the signed-in administrator:
- Microsoft Graph:
User.Read,User.ReadBasic.All,Group.Read.All,GroupMember.Read.All - Azure Service Management:
user_impersonation, used on the Azure Resources page, where Azure checks your own Owner or User Access Administrator role before TeamsPIM is assigned
The portal’s directory reads, such as listing users and groups on the Licenses page, run through the TeamsPIM application’s permissions. That is why TeamsPIM consent must be granted first.