Skip to content

How it works

  1. You request a role. In the Dashboard tab you pick one of your eligible roles, choose a duration, give a reason and select Activate.

  2. PIM decides whether approval is needed. The role’s PIM settings in Microsoft Entra decide. If no approval is needed, the role activates without waiting for anyone and the bot tells you “Self-Activation role has been provisioned”.

  3. Approvers get a card. If approval is needed, each approver set in the role’s PIM settings gets a card in their chat with the TeamsPIM bot. You get a card too, marked “My Request”, so you can follow the request.

  4. An approver decides. The approver adds a justification and selects Approve or Deny on the card. The first decision counts; the other approvers’ cards update to show who decided.

  5. Everyone is updated. Your card shows the result, and you get a Teams activity feed notification. In the Dashboard, your request moves on to Granted or Denied.

  6. You are warned before it ends. Five minutes before your activation ends, the Teams activity feed tells you “Your PIM activation is about to expire”. There is no way to extend an activation in TeamsPIM; request the role again when you need it.

For the details of each step, see Request a role, Approve or deny a request and Notifications.

When you request, activate, deactivate or cancel, TeamsPIM does it with your own identity. When an approver selects Approve or Deny, they sign in once and the action is theirs, so PIM records them as the reviewer. PIM’s own rules still apply — for example, PIM does not let you approve your own request.

TeamsPIM uses its own app permissions for background work: reading role settings and audit logs, looking up users and groups, watching for new requests and sending notifications. Administrators can see the full list in the permissions reference.

What TeamsPIM reads from your role settings

Section titled “What TeamsPIM reads from your role settings”

Each role’s PIM settings in Entra drive what you see in TeamsPIM:

PIM setting What it changes in TeamsPIM
Approval required, and who the approvers are Whether the role shows Self-Activation or Approver Required, and who gets the approval card. Approver groups are supported.
Maximum activation duration The highest value on the Duration (hours) slider.
Multi-factor authentication on activation A notice in the activation drawer; you may be asked to verify.
Conditional Access authentication context A notice in the activation drawer; you may be asked to sign in again.
Ticket information required Ticket number and Ticket system fields in the activation drawer.

How long a request can wait for approval is also set by PIM, not by TeamsPIM.

Your roles, assignments and approvals stay in your organisation’s Microsoft Entra ID and Azure. TeamsPIM reads and acts on them through Microsoft Graph and Azure Resource Manager. Each organisation gets its own dedicated TeamsPIM back end, set up when the subscription is activated. See Data handling for what TeamsPIM stores.