Set up TeamsPIM
From subscription to first request in a handful of steps. Most of it is done once by an administrator; after that, people just open TeamsPIM in Teams.
Check you have these in place
- Microsoft Entra ID P2 or Microsoft Entra ID Governance for the roles you manage
- Privileged Identity Management in use, with eligible assignments for the people who’ll use TeamsPIM
- Approvers, maximum durations and activation requirements set in each role’s PIM settings
- A Global Administrator available to grant admin consent
- Work or school accounts. Personal Microsoft accounts aren’t supported.
Set up your organisation
Open your TeamsPIM subscription
The person who holds the subscription
Setup starts from your organisation’s TeamsPIM subscription in Microsoft AppSource or the Azure Marketplace. Select Configure account now there to open the TeamsPIM activation page.
Read the guideActivate and grant admin consent
The subscription holder, with a Global Administrator
Sign in with the account that holds the subscription, check the subscription details and select Activate. Enter your company name and phone number, use the Admin consent link to approve TeamsPIM for your tenant, then Submit once consent is verified.
Read the guideWait for review and setup
Xertone
Xertone reviews your request, then builds a dedicated TeamsPIM environment for your tenant. Follow progress on the Customer Admin Portal Overview page. Setup can take a few minutes, and the subscription holder gets an email when the subscription is active.
Read the guideAssign licences
The subscription holder or a subscription administrator
In the Customer Admin Portal, open Licenses and switch each user to Licensed, or license every member of a group at once. TeamsPIM then installs itself in each licensed user’s Teams.
Read the guideMake the app available in Teams
A Teams administrator
Allow TeamsPIM in your Teams app permission policies so the automatic install can go through. Optionally, pin it for your users with an app setup policy.
Read the guideConnect Azure subscriptions (optional)
An Azure Owner or User Access Administrator
If people should activate Azure roles through TeamsPIM, open Azure Resources in the Customer Admin Portal and select Assign for each Azure subscription.
Read the guide
Make the first request
Activate a role
Go to My Roles, find an eligible role and select Activate. Set the duration, give a reason and submit.
Request a roleGet it approved
If the role needs approval, its approvers get a card in their TeamsPIM chat and you’re notified when they decide.
Approve or deny