Skip to content

Admin consent

TeamsPIM reads and acts on privileged access data through Microsoft Graph. Several of the permissions it needs can only be granted by an administrator on behalf of the whole organisation, so a tenant-wide admin consent is required before anyone in your tenant can use TeamsPIM, including the Customer Admin Portal.

TeamsPIM asks for a Global Administrator of your tenant: “A Global Administrator of your tenant has to grant admin consent”. If you are not one, copy the consent link and send it to someone who is. Consent must be granted in the same tenant as the purchase.

Microsoft describes tenant-wide consent in Grant tenant-wide admin consent to an application. Review the permissions before you accept; they are listed in the permissions reference.

You can start consent from three places. They all lead to the same Microsoft consent page for the TeamsPIM application.

1. The activation drawer on the landing page

Section titled “1. The activation drawer on the landing page”

During activation, the “Subscription Activation Request” drawer contains an Admin consent link. When consent finishes, the drawer shows “Admin consent verified.” and Submit becomes available. If it shows “Admin consent not verified yet. Complete consent and try again.”, finish consent in the tab that opened and try again.

2. The banner in the Customer Admin Portal

Section titled “2. The banner in the Customer Admin Portal”

If consent is missing, the Customer Admin Portal shows a banner: “TeamsPIM has not been approved for your organisation yet.” It offers two buttons:

  • Grant admin consent opens the consent page, for when you are a Global Administrator.
  • Copy link copies the consent link (“Copy the link to send to a Global Administrator”).

If sign-in to the portal itself fails with “Your organisation hasn’t approved TeamsPIM yet.”, the same applies: a Global Administrator grants consent, then you sign in again.

When you add another directory to a subscription, the “Add a tenant” dialog asks for consent in that tenant: “A Global Administrator of this tenant must grant TeamsPIM admin consent before it can be added.” Use Open consent or Copy link, then Verify.

  1. Open the consent page, or send the link to a Global Administrator.
  2. The Global Administrator signs in, reviews the permissions and accepts.
  3. Return to TeamsPIM and verify, or reload the page.

TeamsPIM uses two Microsoft Entra app registrations. The consent described on this page is for the first, TeamsPIM.

Registration What it asks for
TeamsPIM (the app in Teams and its back end) Microsoft Graph delegated and application permissions for PIM, plus delegated Azure Service Management access
TeamsPIM Customer Admin Portal Delegated permissions only: Microsoft Graph Group.Read.All, GroupMember.Read.All, User.Read and User.ReadBasic.All, and Azure Service Management user_impersonation

The Customer Admin Portal reads your directory through the TeamsPIM application’s permissions. That is why TeamsPIM consent has to be in place before the portal can list your users and groups.

See the permissions reference for every permission and why it is needed.