Skip to content

Data handling

TeamsPIM is a front end to Microsoft Entra Privileged Identity Management. Your privileged access data stays where it already is; TeamsPIM stores only what it needs to run the service.

For the formal terms, see the Xertone privacy policy and terms.

Your PIM data stays in Microsoft Entra and Azure

Section titled “Your PIM data stays in Microsoft Entra and Azure”

Roles, eligible and active assignments, role settings and approvals remain in your Microsoft Entra ID and Azure. TeamsPIM reads them and acts on them through Microsoft Graph and Azure Resource Manager. It does not keep its own copy of your role assignments.

TeamsPIM acts as For
The signed-in user Requesting, activating, deactivating and cancelling activations, and approving or denying requests
The TeamsPIM application Reading role settings and audit logs, resolving users and groups, monitoring requests and sending notifications

Because user actions run with the user’s identity, Microsoft Entra and PIM audit logs show the real requestor and the real approver. The full list is in the permissions reference.

Data Contents
Activation request Tenant ID, subscription ID, plan, the purchaser’s object ID, email and phone number, company name, and the request status
Licences Each licensed user’s object ID and the subscription the licence belongs to
Subscription settings Additional tenant IDs and the object IDs of subscription administrators
Feedback Whatever a user submits through the Feedback form in the app

Each customer tenant has its own TeamsPIM back end. It holds:

  • Teams conversation references, so the bot can send cards and messages to your users.
  • Short-lived request state used while a request is processed. It expires after 36 hours.
  • An approval audit log: who approved or denied which request, the justification given, and when. It is retained for 730 days with interactive access, and 2,556 days in total.

The TeamsPIM tab caches a user’s recent requests on their device for 24 hours.

TeamsPIM does not store secrets from your organisation. You never give TeamsPIM a password, client secret or key: access comes from the admin consent your Global Administrator grants and from each user’s own sign-in.

For data questions, including what happens to data after cancelling, contact Xertone through support.