What is TeamsPIM
TeamsPIM is a Microsoft Teams app, published by Xertone, that brings Microsoft Entra Privileged Identity Management (PIM) into Teams. Instead of going to the Entra or Azure portal, you request your privileged roles and approvers decide on them without leaving Teams.
In short: PIM without the portal.
Two places in Teams
Section titled “Two places in Teams”TeamsPIM is a personal app. It has three tabs: Chat, Dashboard and About. The work is split between the first two.
| Where | What you do there |
|---|---|
| Dashboard tab | Request and activate your eligible roles, see your active assignments, deactivate a role, cancel a pending request and look at your request history. |
| Chat with the TeamsPIM bot | Approve or deny requests on cards. The bot also tracks the requests you raise and tells you when they are decided. |
The Dashboard tab has no approver screen. If a request needs your approval, it arrives as a card in your chat with the TeamsPIM bot.
What you can request
Section titled “What you can request”TeamsPIM works with three kinds of PIM eligibility:
- Microsoft Entra roles at directory scope. Roles scoped to an application or an administrative unit are not supported.
- PIM for Groups — Owner or Member of a group.
- Azure roles at subscription and resource-group scope.
What TeamsPIM does not replace
Section titled “What TeamsPIM does not replace”TeamsPIM is a way to use PIM, not a replacement for it. Your PIM set-up stays in Microsoft Entra:
- Your eligible assignments are created in PIM. TeamsPIM shows the ones you already have; it does not create them.
- Approvers, maximum activation duration and activation requirements (such as multi-factor authentication or ticket information) are set in each role’s PIM settings in Entra. TeamsPIM reads them and follows them. See Approvers and role settings.
- Your roles, assignments and approvals stay in your organisation’s Microsoft Entra ID and Azure.
Next: How it works.