Skip to content
Features

Privileged access, one chat away

TeamsPIM gives requestors a dashboard and approvers an inbox-free way to decide, all inside Microsoft Teams and all enforced by Microsoft Entra PIM.

For requestors

Ask for access in a few clicks

The Dashboard tab lists everything you're eligible for and shows exactly what each role requires before you ask.

The roles you can activate: Eligible Assignments under My Roles, Entra Roles in the TeamsPIM Dashboard, each role showing whether it needs an approver, with Activate buttons. Sample data.
  • My Roles shows your eligible and active assignments for Entra roles, groups and Azure resources, with search and filters.
  • See at a glance whether a role is Self-Activation or Approver Required, and who the approvers are.
  • Choose the duration up to the role’s maximum, set a custom start time, and add ticket details when the role asks for them.
  • A notice tells you up front when a role needs multi-factor authentication, a Conditional Access authentication context or ticket information.
  • Most Frequent PIM Requests puts your usual roles one Activate away.
For approvers

Decide without opening the portal

Approvers named in a role's PIM settings get an adaptive card in their personal TeamsPIM chat when a request needs them.

Approve or deny on the card: a New Entra ID Request card in the approver’s TeamsPIM chat with the role, requester and reason, a justification entered and the Approve button highlighted. Sample data.
  • Every card shows the role, group or Azure resource, who asked, their reason, any ticket number, and how long they need it.
  • Add a justification, then select Approve or Deny. The decision is made with your own identity, so PIM records you as the reviewer.
  • The first decision wins. Every other approver’s card and the requestor’s card update to show who decided.
  • Requestors can see their own request card in their chat too, and it updates when a decision is made.
After a decision

Everyone knows where a request stands

See the time left: a request card’s progress bar reading Submit, Reviewed, Granted, with a countdown ring showing 00:28:08. Sample data.
  • Latest Requests tracks each request from Submit through Pending Approval to Granted, with a countdown while the role is active.
  • Approvals and denials arrive as Teams activity-feed notifications.
  • A reminder arrives five minutes before an activation ends.
  • My Requests keeps a month of history. Cancel a request while it’s pending, or deactivate a role as soon as you’re done.
Coverage

Roles, groups and Azure resources

TeamsPIM covers the three kinds of PIM eligibility most teams use every day.

Microsoft Entra roles

Activate directory roles such as Global Reader or Password Administrator at directory scope.

PIM for Groups

Activate membership or ownership of Security and Microsoft 365 groups managed by PIM.

Azure resources

Activate Azure roles on subscriptions and resource groups, once an administrator connects the subscription to TeamsPIM.

Insight

PIM reports for the people who need them

Users with an active Global Administrator, Privileged Role Administrator, Security Administrator, Global Reader or Security Reader role get a PIM reports page in the Dashboard.

Assignment distribution

See how eligible and active assignments are spread across roles and scopes.

Activation trends

Activations over the last seven days, plus new eligible and active members.

Activity by role

Which roles, groups and resources were used in the last 30 days.

Everywhere

On every device Teams runs on

Desktop and web

The full Dashboard and the approval cards in the Teams desktop app and Teams on the web.

Mobile

The Dashboard adapts to small screens with a collapsible menu, and approval cards work in Teams mobile, so approvers can decide from their phone.

Your Teams theme

TeamsPIM follows the theme you use in Teams: light, dark or high contrast.

For administrators

Simple to roll out and manage

The TeamsPIM Customer Admin Portal is where you manage licences, Azure access and directories. Everything else stays in Microsoft Entra PIM, where you already configure it.

Licences by user or group

Assign licences to individual users, or to every member of a group at once.

Automatic app install

Assigning a licence also installs TeamsPIM in that user’s Teams, wherever your Teams app policies allow it.

Azure subscriptions

Connect the Azure subscriptions whose roles people should activate through TeamsPIM.

Multiple directories

Add up to 10 tenants to one subscription, so people can switch directory inside TeamsPIM.

Delegated administration

Add colleagues as subscription administrators so they can manage licences too.

Your PIM data stays put

Roles, assignments and approvals stay in Microsoft Entra ID and Azure. TeamsPIM reads and acts on them through Microsoft APIs.

TeamsPIM — PIM without the portal

Ready to try it?

Follow the setup guide to subscribe, grant consent and assign licences. Then your people can request and approve roles right in Teams.