Azure resources
TeamsPIM handles PIM requests for Azure roles at subscription and resource-group scope. For TeamsPIM to handle requests on an Azure subscription, you assign TeamsPIM to that subscription on the Azure Resources page of the Customer Admin Portal. Nothing is assigned automatically, so Azure requests work only on subscriptions you have assigned.
Microsoft Entra roles and PIM for Groups do not need this step.
What Assign does
Section titled “What Assign does”Assign gives the TeamsPIM application the Azure built-in Role Based Access Control Administrator role (RBAC Administrator) on the Azure subscription. Unassign removes that role assignment, and TeamsPIM stops handling requests for the subscription.
Users still act as themselves. When someone requests, activates or deactivates an Azure role in TeamsPIM, the action uses their own Azure identity, so Azure and PIM record them as the actor.
Who can assign
Section titled “Who can assign”To assign or unassign, you need Owner or User Access Administrator on the Azure subscription, and access to the subscription in the Customer Admin Portal (the purchaser or an added administrator). Having read access to the subscription is enough to see it listed, but not to change TeamsPIM’s access.
Assign TeamsPIM to a subscription
Section titled “Assign TeamsPIM to a subscription”- In the Customer Admin Portal, open Azure Resources. The page reads “Azure subscriptions your account can access. Assign TeamsPIM to a subscription so it can handle PIM requests for that subscription’s Azure resources, or unassign to stop it.”
- Choose your TeamsPIM subscription in “Select a subscription”.
- Choose the directory in “Select a tenant”. The list contains your own tenant and any additional directories added to the subscription.
- Find the Azure subscription, using Search if needed.
- Select Assign. The button changes to Unassign once TeamsPIM holds the role.
Use the refresh button to reload the list after changes made elsewhere.
Errors
Section titled “Errors”| Message | Cause | Fix |
|---|---|---|
“This tenant requires multi-factor authentication to access Azure.” (AZURE_MFA_REQUIRED) |
Your account has not completed multi-factor authentication in that tenant, so Azure refused the request. | Sign in to portal.azure.com, switch to that directory and complete the MFA prompt. Then sign out of the Customer Admin Portal, sign back in and pick the tenant again. |
“You cannot change access at this scope.” (INSUFFICIENT_AZURE_RBAC) |
You do not have Owner or User Access Administrator on the subscription. | Get one of those roles, or ask someone who has it to assign TeamsPIM. |
“This tenant is not linked to the subscription.” (TENANT_NOT_LINKED) |
The tenant you picked is not in the subscription’s additional tenant IDs. | Add it in Subscription Settings, then come back. |
“This subscription’s tenant has not granted TeamsPIM admin consent.” (TENANT_CONSENT_MISSING) |
That tenant has not consented to TeamsPIM. | Grant consent for that tenant; see Admin consent. |
| “Sign-in for this tenant did not complete.” | Signing in to the other tenant was interrupted. | Pick the tenant again to retry. |
If an assignment fails for another reason, you see “Assign app failed.” or “Unassign app failed.” followed by the error Azure returned.