Skip to content

Request a role

Use the Dashboard tab to activate a role you are eligible for. If the role needs approval, your request goes to the approvers; if not, it activates without an approval step.

  1. In Teams, open TeamsPIM and select the Dashboard tab.

  2. Go to My Roles → Entra Roles → Eligible Assignments. For a group or an Azure role, choose Groups or Azure Resources instead of Entra Roles.

    Shortcut: if the role is listed under Most Frequent PIM Requests on the Overview page, select Activate there.

  3. Find the role. You can search by role name or description, or use Filter to narrow the list.

  4. Check the role’s “Activation:” line:

    • Self-Activation — no approval needed.
    • Approver Required — the request goes to the approvers shown next to it.
  5. Select Activate. A drawer opens, titled “Activate - “ followed by the role name.

  6. Read any requirements notice at the top of the drawer, then fill in the fields (see the table below). A reason is always required.

  7. Select Activate. You see “Request created successfully.” with a Go to overview link.

The Eligible Assignments page under My Roles, Entra Roles, with the Activate - Azure DevOps Administrator drawer open showing Custom activation start time, the Duration (hours) slider, the Reason box highlighted, and the Activate and Cancel buttons. Sample data.
Field What to enter
“Custom activation start time” Leave it off to start now. Turn it on to choose a start date, time and time zone. The time zone defaults to your browser’s.
“Duration (hours)” Use the slider or type a value, in half-hour steps. The minimum is 0.5 hours. The maximum is the role’s PIM maximum, and the value starts at that maximum.
“Ticket number” Only shown when the role’s PIM settings require ticket information. Required when shown, for example INC0012345. Up to 128 characters.
“Ticket system” Shown with Ticket number. Optional, for example ServiceNow. Up to 128 characters.
“Reason (max 500 characters)” Always required. Tell the approvers why you need the role.

If the role’s PIM settings add extra checks, the drawer tells you before you submit, for example:

This role requires multi-factor authentication to activate.

The notice can name multi-factor authentication, a Conditional Access authentication context and ticket information. When an authentication context is required, it adds “You may be asked to sign in again.”

If you see “Additional verification required”, select Verify and complete the sign-in. If you see “Set up multi-factor authentication”, register at aka.ms/mfasetup, then sign out of Teams and back in.

Go to My Roles → Entra Roles → Eligible Assignments. Each card shows “End Date time:” (or “Permanent”), “Scope:”, “Membership:” and “Activation:”.

Only directory-scoped roles are supported. Roles scoped to an application or an administrative unit cannot be activated in TeamsPIM.

  • Approval needed: the request shows Pending Approval. Each approver gets a card in their chat with the TeamsPIM bot, and you get a card marked “My Request” so you can follow it. See Track your requests.
  • No approval needed: the role activates without an approval step, and the bot sends you “Self-Activation role has been provisioned”.

Activation can take a few seconds to show. If the role is not listed under Active Assignments yet, refresh the tab.

  • “Request creating failed.” followed by a message: the message comes from Microsoft Entra and explains why PIM refused the request.
  • A request for this role is already pending: you cannot make a second request for the same role while one is waiting for approval. Wait for the decision, or cancel the pending request first.
  • “No TeamsPIM license assigned”: ask your administrator to assign you a licence, then reopen the app.

More fixes are in Troubleshooting.