Skip to content
Get started

Set up TeamsPIM

From subscription to first request in a handful of steps. Most of it is done once by an administrator; after that, people just open TeamsPIM in Teams.

Before you begin

Check you have these in place

  • Microsoft Entra ID P2 or Microsoft Entra ID Governance for the roles you manage
  • Privileged Identity Management in use, with eligible assignments for the people who’ll use TeamsPIM
  • Approvers, maximum durations and activation requirements set in each role’s PIM settings
  • A Global Administrator available to grant admin consent
  • Work or school accounts. Personal Microsoft accounts aren’t supported.

Full requirements →

For administrators

Set up your organisation

  1. Open your TeamsPIM subscription

    The person who holds the subscription

    Setup starts from your organisation’s TeamsPIM subscription in Microsoft AppSource or the Azure Marketplace. Select Configure account now there to open the TeamsPIM activation page.

    Read the guide
  2. Activate and grant admin consent

    The subscription holder, with a Global Administrator

    Sign in with the account that holds the subscription, check the subscription details and select Activate. Enter your company name and phone number, use the Admin consent link to approve TeamsPIM for your tenant, then Submit once consent is verified.

    Read the guide
  3. Wait for review and setup

    Xertone

    Xertone reviews your request, then builds a dedicated TeamsPIM environment for your tenant. Follow progress on the Customer Admin Portal Overview page. Setup can take a few minutes, and the subscription holder gets an email when the subscription is active.

    Read the guide
  4. Assign licences

    The subscription holder or a subscription administrator

    In the Customer Admin Portal, open Licenses and switch each user to Licensed, or license every member of a group at once. TeamsPIM then installs itself in each licensed user’s Teams.

    Read the guide
  5. Make the app available in Teams

    A Teams administrator

    Allow TeamsPIM in your Teams app permission policies so the automatic install can go through. Optionally, pin it for your users with an app setup policy.

    Read the guide
  6. Connect Azure subscriptions (optional)

    An Azure Owner or User Access Administrator

    If people should activate Azure roles through TeamsPIM, open Azure Resources in the Customer Admin Portal and select Assign for each Azure subscription.

    Read the guide
For everyone

Make the first request

  1. Open TeamsPIM

    Open the TeamsPIM app in Teams and select the Dashboard tab.

    Tour of the app
  2. Activate a role

    Go to My Roles, find an eligible role and select Activate. Set the duration, give a reason and submit.

    Request a role
  3. Get it approved

    If the role needs approval, its approvers get a card in their TeamsPIM chat and you’re notified when they decide.

    Approve or deny
Need a hand?

We’re here to help