Data handling
TeamsPIM is a front end to Microsoft Entra Privileged Identity Management. Your privileged access data stays where it already is; TeamsPIM stores only what it needs to run the service.
For the formal terms, see the Xertone privacy policy and terms.
Your PIM data stays in Microsoft Entra and Azure
Section titled “Your PIM data stays in Microsoft Entra and Azure”Roles, eligible and active assignments, role settings and approvals remain in your Microsoft Entra ID and Azure. TeamsPIM reads them and acts on them through Microsoft Graph and Azure Resource Manager. It does not keep its own copy of your role assignments.
Who acts: the user or the app
Section titled “Who acts: the user or the app”| TeamsPIM acts as | For |
|---|---|
| The signed-in user | Requesting, activating, deactivating and cancelling activations, and approving or denying requests |
| The TeamsPIM application | Reading role settings and audit logs, resolving users and groups, monitoring requests and sending notifications |
Because user actions run with the user’s identity, Microsoft Entra and PIM audit logs show the real requestor and the real approver. The full list is in the permissions reference.
What TeamsPIM stores
Section titled “What TeamsPIM stores”| Data | Contents |
|---|---|
| Activation request | Tenant ID, subscription ID, plan, the purchaser’s object ID, email and phone number, company name, and the request status |
| Licences | Each licensed user’s object ID and the subscription the licence belongs to |
| Subscription settings | Additional tenant IDs and the object IDs of subscription administrators |
| Feedback | Whatever a user submits through the Feedback form in the app |
Your tenant’s dedicated back end
Section titled “Your tenant’s dedicated back end”Each customer tenant has its own TeamsPIM back end. It holds:
- Teams conversation references, so the bot can send cards and messages to your users.
- Short-lived request state used while a request is processed. It expires after 36 hours.
- An approval audit log: who approved or denied which request, the justification given, and when. It is retained for 730 days with interactive access, and 2,556 days in total.
On users’ devices
Section titled “On users’ devices”The TeamsPIM tab caches a user’s recent requests on their device for 24 hours.
Secrets
Section titled “Secrets”TeamsPIM does not store secrets from your organisation. You never give TeamsPIM a password, client secret or key: access comes from the admin consent your Global Administrator grants and from each user’s own sign-in.
Questions
Section titled “Questions”For data questions, including what happens to data after cancelling, contact Xertone through support.