Requirements
For your organisation
Section titled “For your organisation”- An active TeamsPIM subscription, bought on Microsoft AppSource or the Azure Marketplace.
- Privileged Identity Management in use, with eligible assignments for Entra roles, groups or Azure resources.
- Microsoft Entra ID P2 or Microsoft Entra ID Governance licences for the roles you manage with PIM.
- Admin consent. A Global Administrator must grant admin consent before anyone in the tenant can use the app. See Admin consent.
- Approvers set in Entra. Approvers are configured in each role’s PIM settings in Microsoft Entra. TeamsPIM reads them; it does not store its own list. See Approvers and role settings.
- For Azure roles: TeamsPIM assigned to each Azure subscription it should handle requests for. See Azure resources.
- The app allowed in Teams by your Teams administrator. See Deploy in Teams.
For each user
Section titled “For each user”- A work or school account in your organisation’s Microsoft Entra ID. Personal Microsoft accounts are not supported.
- A TeamsPIM licence assigned to you by an administrator. Without one, the app shows “No TeamsPIM license assigned”. See Assign licences.
- An eligible assignment in PIM for the role, group or Azure role you want to activate. TeamsPIM only shows eligibility you already have.
- Multi-factor authentication set up, if your roles require it. If you have not registered, the app shows “Set up multi-factor authentication”.
Approvers need a licence too
Section titled “Approvers need a licence too”Approval cards only reach approvers who have a TeamsPIM licence. If someone is an approver in PIM but has no TeamsPIM licence, they will not get cards in Teams.