Getting Started with TeamsPIM
Welcome aboard. This page walks you from your new subscription to your first approved role activation in Microsoft Teams — what you need in place, what we do together, and who to ask when you need a hand.
What you need in place
TeamsPIM works on top of your existing Microsoft environment. These four things belong to your tenant, so it is worth confirming them before the deployment call.
| Microsoft licensing | Microsoft Entra PIM itself requires Microsoft Entra ID P2 or Microsoft Entra ID Governance licensing for the people who use it. These are Microsoft licenses held by your organization — they are not included with TeamsPIM. |
|---|---|
| An Entra administrator for consent | A Global Administrator or Privileged Role Administrator has to grant admin consent for TeamsPIM's Microsoft Graph permissions. Nothing connects to your tenant until they do. |
| Someone who can add Teams apps | An administrator with rights in the Microsoft Teams admin center, so the TeamsPIM app can be added and made available to the right people. |
| An existing PIM configuration | Eligible role assignments already set up in Microsoft Entra PIM. TeamsPIM surfaces your configuration in Teams — it does not create a parallel privilege store or replace your policies. See how TeamsPIM connects. |
Four steps to your first activation
Our team runs these with you — you do not work through them alone.
Install the Teams app
We provide your TeamsPIM app package and walk your Teams administrator through adding it in the Teams admin center and making it available to your users.
Grant admin consent
Your Entra administrator reviews each Microsoft Graph permission — we explain the reason for every one — and grants consent. This is the step that connects TeamsPIM to your tenant.
Onboard your people
Add your requesters and approvers, have them pin TeamsPIM in Teams, and confirm each person sees the roles and approvals they should — and nothing they should not.
Run your first request
An eligible user requests a role from the Teams dashboard, the approver acts on an Adaptive Card in Teams, and the activation lands in your Entra PIM audit log. That is the whole loop.
Installing from Microsoft AppSource
TeamsPIM's AppSource listing is on the way but is not published yet, so installation today is guided by our team — which also means you get a permissions walkthrough rather than a silent install. We will update this page with self-serve AppSource steps as soon as the listing goes live.
Who does what after setup
Three groups of people touch TeamsPIM day to day. Knowing which is which makes the rollout conversation much shorter.
Requesters
People with eligible role assignments. They open TeamsPIM in Teams, see the roles they can activate across Entra ID, Groups, and Azure resources, and request activation with a justification — without leaving Teams for the Azure portal.
Approvers
People named as approvers in your PIM policies. Requests arrive as Adaptive Cards in Teams with the full justification and context, and they approve or deny in place. Other approvers see that the request has been handled.
Administrators
Your IT and identity admins. They manage who has the TeamsPIM app, keep eligibility and approval policies in Entra PIM as they always have, and use the role status dashboard for one view across all three role types.
Common setup questions
Most tenants are live the same day. Installing the Teams app and granting admin consent is typically under an hour with your admins in the room; onboarding requesters and approvers happens alongside it. The longest step is usually scheduling your admins, not the technical work.
No. TeamsPIM reads and acts against the Microsoft Entra PIM setup you already have — your role definitions, eligibility, approval requirements, and activation policies stay exactly as they are. TeamsPIM changes where your team does the work, not the rules the work follows.
Your Entra administrator sees the full list on the consent screen before granting anything. We walk your security team through every permission and the business reason for each one before you consent — nothing connects to your tenant until an administrator approves it.
Yes, and we recommend it. Start with one team that already uses Entra PIM daily — a handful of requesters and their approvers. Once the request-to-activation flow is proven in your environment, widen the rollout to the rest of the organization.
Add them to the TeamsPIM app in Teams the same way you did the first group. Billing follows your licensed user count — get in touch when your numbers change and we will adjust your subscription.
Yes. Requests, approvals, and activations performed through TeamsPIM are written to your Microsoft Entra PIM audit log like any other PIM action, because TeamsPIM performs them through Microsoft Graph against your tenant.
Not answered here? The product FAQ and security page cover most of the rest.
Stuck on a step?
Tell us your organization name and where you got to — we will pick it up from there. Deployment help is included with every subscription.