| Activation |
Turning an eligible assignment into an active one for a limited time. In TeamsPIM you select Activate on a role, give a reason and choose a duration. See Request a role. |
| Active assignment |
A role, group membership or ownership you hold right now. It can be time-bound, for example after an activation, or permanent. TeamsPIM shows them under My Roles > Active Assignments. |
| Admin consent |
A tenant-wide approval, granted by a Global Administrator, that lets TeamsPIM use the Microsoft Graph permissions it needs. Required before anyone in the tenant can use TeamsPIM. See Admin consent. |
| Approver |
A person, or member of a group, named in a role’s PIM settings who can approve or deny activation requests for that role. In TeamsPIM, approvers act on cards in their chat with the TeamsPIM bot. |
| Authentication context |
A Microsoft Entra Conditional Access feature. A role’s PIM settings can require one on activation, so the user must meet a Conditional Access policy, such as a stronger sign-in, before the role activates. TeamsPIM shows “Additional verification required” when one applies. |
| Customer Admin Portal |
The TeamsPIM web portal where administrators assign licences, assign TeamsPIM to Azure subscriptions and add additional directories. See Customer Admin Portal reference. |
| Directory (tenant) |
A Microsoft Entra organisation, identified by a tenant ID. TeamsPIM works in your own tenant and in any additional tenants you add to your subscription. Users move between them with Switch Directory. |
| Eligible assignment |
A role, group membership or ownership you are allowed to activate but do not hold until you do. Eligible assignments are created in Microsoft Entra PIM, not in TeamsPIM. TeamsPIM shows them under My Roles > Eligible Assignments. |
| Justification |
The business reason given with a request or a decision. Requestors always enter one (“Reason”), and approvers enter one when they approve or deny. |
| PIM (Privileged Identity Management) |
The Microsoft Entra service for just-in-time, time-bound privileged access with approval, MFA and audit. TeamsPIM brings it into Microsoft Teams. |
| PIM for Groups |
PIM applied to membership or ownership of a Microsoft Entra security group or Microsoft 365 group. In TeamsPIM you activate them as Member or Owner. |
| Role settings (PIM policy) |
The per-role rules in Microsoft Entra PIM: whether approval is needed and who approves, the maximum activation duration, and whether MFA, an authentication context, a justification or ticket information is required. TeamsPIM reads and follows them. See Approvers and role settings. |
| Self-activation |
Activating a role whose settings do not require approval. TeamsPIM labels these Self-Activation; the request goes through without waiting for an approver. |
| Time-bound vs permanent |
A time-bound assignment has an end date and time; a permanent one does not. TeamsPIM shows the end date or “Permanent” on each card, and the Active Assignments tab has Time-bound Activation and Permanent Activation views. |
| TeamsPIM licence |
A seat in your TeamsPIM subscription, assigned to one user in the Customer Admin Portal. Every requestor and approver needs one. See Assign licences. |