Skip to content

Approvers and role settings

TeamsPIM has no approval rules of its own. Who approves a request, how long an activation can last and what a requestor must provide are all set in Microsoft Entra Privileged Identity Management role settings (also called PIM policies). TeamsPIM reads those settings and follows them.

To change who approves a role, or anything else about how it activates, change the role settings in Microsoft Entra. There is nothing to configure in TeamsPIM.

Role settings are defined per role, and separately for each kind of PIM:

Role type Where Microsoft Learn
Microsoft Entra roles Microsoft Entra admin center > ID Governance > Privileged Identity Management > Microsoft Entra roles > Roles > role > Role settings Configure Microsoft Entra role settings in PIM
PIM for Groups Settings for the group’s Member or Owner role Configure PIM for Groups settings
Azure resource roles Settings for the role on the subscription or resource group Configure Azure resource role settings in PIM

TeamsPIM supports Microsoft Entra directory roles at directory scope, PIM for Groups membership and ownership, and Azure roles at subscription and resource-group scope. For Azure roles, TeamsPIM must also be assigned to the Azure subscription.

Role setting in PIM What users see in TeamsPIM
Require approval to activate and the selected approvers The role card shows “Activation:” Approver Required with the approvers’ pictures. Without approval it shows Self-Activation. If TeamsPIM cannot read the role’s settings it shows “Not available”.
Activation maximum duration The “Duration (hours)” slider in the activation drawer goes up to this maximum and starts at it.
On activation, require multifactor authentication The drawer shows “This role requires multi-factor authentication to activate.”
On activation, require Microsoft Entra Conditional Access authentication context The drawer shows that the role requires a Conditional Access authentication context and adds “You may be asked to sign in again.” The user may see “Additional verification required” with a Verify button.
Require ticket information on activation The drawer adds “Ticket number” (required) and “Ticket system” (optional) fields.

TeamsPIM always asks for a reason (“Reason (max 500 characters)”), whatever the role settings say.

For Conditional Access authentication context, see Conditional Access: Target resources, Authentication context.

  • Approvers get cards in Teams. When a request needs approval, each approver named in the role settings, including members of approver groups, receives an approval card in their personal chat with the TeamsPIM bot. See Approve or deny a request.
  • Approvers need a TeamsPIM licence. An approver without a licence does not receive cards. Assign them a licence as you would a requestor.
  • Approvers act as themselves. Approving on a card signs the approver in, so PIM records the approver, not TeamsPIM, as the reviewer.
  • No self-approval. PIM does not let anyone approve their own request, and TeamsPIM follows that.
  • The first decision wins. Once one approver approves or denies, the other approvers’ cards update to show who decided.
  • Approval timeout is PIM’s. How long a request can wait for approval is governed by PIM, not by TeamsPIM.
  • It does not store or configure approvers.
  • It does not create eligible assignments. Make people eligible for roles in Microsoft Entra PIM as usual.
  • It does not extend or renew activations. When an activation ends, the user requests the role again.