Security

Security and Data Handling

TeamsPIM is built to add workflow convenience without changing your security posture. This page explains exactly how it connects to your tenant, what it touches, and what it keeps.

Architecture

How TeamsPIM connects

TeamsPIM is a Microsoft Teams application operated by Xertone on Microsoft Azure. It authenticates through Microsoft Entra ID and reaches your Microsoft Entra PIM environment exclusively through Microsoft Graph.

Delivered as a Teams app in your tenant
Microsoft Entra ID sign-in with admin consent
All PIM operations via Microsoft Graph
Service hosted on Microsoft Azure
Data Handling

What we query, cache, and store

We keep this precise on purpose — privileged-access tooling should never be vague about data.

Queried live, not persistedPIM role definitions, assignments, eligibility, and activation details are read in real time from Microsoft Graph when your users use TeamsPIM. This data is not persisted in Xertone systems.
Cached brieflyTemporary Adaptive Card state needed to render approvals in Teams. This cache auto-expires.
StoredYour subscription and tenant configuration (organization details, plan, and app settings) — the minimum needed to operate the service for you.
Where the service runsXertone operates TeamsPIM on Microsoft Azure infrastructure. We'll walk through the hosting and isolation architecture with your security team during a trial or procurement review.
Operational telemetryService-health and error telemetry is collected to run TeamsPIM reliably, and is designed not to include your PIM data.
Authentication & Permissions

Your identity provider stays in charge

Microsoft Entra ID sign-in

Users sign in with their existing Microsoft Entra ID accounts. TeamsPIM introduces no separate credentials and no external identity providers.

Admin consent, up front

Your Microsoft Entra ID administrator reviews and grants the app's Microsoft Graph permissions before anyone can use TeamsPIM. Nothing connects without your consent.

Permissions, explained

We walk your security team through every Microsoft Graph permission TeamsPIM requests — and the business reason for each — before you grant admin consent.

Lifecycle

Retention, deletion, and disclosure

When you remove TeamsPIMRemoving the app and revoking consent in Microsoft Entra ID ends TeamsPIM's access to your tenant. Cached Adaptive Card state expires on its own; subscription configuration is removed in line with our Privacy Policy and your agreement.
Deletion requestsSend deletion requests to contact@xertone.com and we will action them in line with our Privacy Policy.
Responsible disclosureIf you believe you've found a security vulnerability, email contact@xertone.com with "Security" in the subject. We review every report and will keep you informed.
Security reviewsProcurement or security questionnaire? We're glad to work through it — contact us and we'll provide the documentation your review needs.

Bring Your Security Team to the Trial

Free trials include a permissions walkthrough and direct access to our team for security questions.