Skip to content

Permissions reference

This page lists the permissions of the TeamsPIM application, the one a Global Administrator consents to (see Admin consent), and of the TeamsPIM Customer Admin Portal. Microsoft describes each Graph permission in the Microsoft Graph permissions reference.

TeamsPIM works in two ways:

  • As the signed-in user (delegated). Requesting, activating, deactivating and cancelling activations, and approving or denying requests, run with the user’s own identity. Microsoft Entra and PIM record the user as the actor.
  • As the app (application). Reading role settings and audit logs, resolving users and groups, monitoring requests and sending notifications run as the TeamsPIM application.

TeamsPIM: delegated Microsoft Graph permissions

Section titled “TeamsPIM: delegated Microsoft Graph permissions”
Permission Why
openid, profile, email, User.Read Sign-in
RoleManagement.ReadWrite.Directory Request, activate, deactivate and cancel Microsoft Entra role activations as the user
PrivilegedAccess.ReadWrite.AzureAD PIM for Microsoft Entra roles
PrivilegedAccess.ReadWrite.AzureADGroup PIM for Groups requests as the user
PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup PIM for Groups requests as the user

TeamsPIM: application Microsoft Graph permissions

Section titled “TeamsPIM: application Microsoft Graph permissions”
Permission Why
User.Read.All Resolve requestors and approvers
GroupMember.Read.All Resolve approver groups and their members
Application.Read.All Service principal lookups
AuditLog.Read.All Request history, most frequent requests and PIM reports
RoleManagement.Read.Directory Role definitions and schedules, for reports
RoleManagementPolicy.Read.Directory Read role settings: approvers and activation requirements
RoleManagementPolicy.Read.AzureADGroup Read role settings for PIM for Groups
RoleAssignmentSchedule.ReadWrite.Directory Microsoft Entra role requests processed by the bot
PrivilegedAssignmentSchedule.Read.AzureADGroup Monitor PIM for Groups requests
PrivilegedAssignmentSchedule.ReadWrite.AzureADGroup Process PIM for Groups requests
PrivilegedAccess.Read.AzureAD Monitor PIM requests
TeamsActivity.Send Send Teams activity feed notifications
TeamsAppInstallation.ReadForUser.All Check whether the TeamsPIM app is installed for a user
TeamsAppInstallation.ReadWriteSelfForUser.All Install TeamsPIM for users when they are given a licence
AppCatalog.Read.All Find TeamsPIM in your organisation’s Teams app catalogue
Permission Why
Azure Service Management user_impersonation (delegated) Azure resource role requests run with the user’s own Azure identity
Teams single sign-on TeamsPIM signs users in silently inside Teams

No Teams resource-specific consent (RSC) permissions. TeamsPIM is a personal app only: a bot chat and tabs for each user, with no team or channel tabs and no message extensions.

Approving or denying on a card signs the approver in, so the decision is made with the approver’s own identity and PIM records them as the reviewer. See Approve or deny a request.

Azure: RBAC Administrator, only where you assign it

Section titled “Azure: RBAC Administrator, only where you assign it”

TeamsPIM holds no Azure role by default. When someone with Owner or User Access Administrator selects Assign on the Azure Resources page, TeamsPIM receives the built-in Role Based Access Control Administrator role on that Azure subscription. Unassign removes it.

TeamsPIM Customer Admin Portal permissions

Section titled “TeamsPIM Customer Admin Portal permissions”

The portal’s own registration has delegated permissions only, so it acts as the signed-in administrator:

  • Microsoft Graph: User.Read, User.ReadBasic.All, Group.Read.All, GroupMember.Read.All
  • Azure Service Management: user_impersonation, used on the Azure Resources page, where Azure checks your own Owner or User Access Administrator role before TeamsPIM is assigned

The portal’s directory reads, such as listing users and groups on the Licenses page, run through the TeamsPIM application’s permissions. That is why TeamsPIM consent must be granted first.