Security and Data Handling
TeamsPIM is built to add workflow convenience without changing your security posture. This page explains exactly how it connects to your tenant, what it touches, and what it keeps.
How TeamsPIM connects
TeamsPIM is a Microsoft Teams application operated by Xertone on Microsoft Azure. It authenticates through Microsoft Entra ID and reaches your Microsoft Entra PIM environment exclusively through Microsoft Graph.
What we query, cache, and store
We keep this precise on purpose — privileged-access tooling should never be vague about data.
| Queried live, not persisted | PIM role definitions, assignments, eligibility, and activation details are read in real time from Microsoft Graph when your users use TeamsPIM. This data is not persisted in Xertone systems. |
|---|---|
| Cached briefly | Temporary Adaptive Card state needed to render approvals in Teams. This cache auto-expires. |
| Stored | Your subscription and tenant configuration (organization details, plan, and app settings) — the minimum needed to operate the service for you. |
| Where the service runs | Xertone operates TeamsPIM on Microsoft Azure infrastructure. We'll walk through the hosting and isolation architecture with your security team during a trial or procurement review. |
| Operational telemetry | Service-health and error telemetry is collected to run TeamsPIM reliably, and is designed not to include your PIM data. |
Your identity provider stays in charge
Microsoft Entra ID sign-in
Users sign in with their existing Microsoft Entra ID accounts. TeamsPIM introduces no separate credentials and no external identity providers.
Admin consent, up front
Your Microsoft Entra ID administrator reviews and grants the app's Microsoft Graph permissions before anyone can use TeamsPIM. Nothing connects without your consent.
Permissions, explained
We walk your security team through every Microsoft Graph permission TeamsPIM requests — and the business reason for each — before you grant admin consent.
Retention, deletion, and disclosure
| When you remove TeamsPIM | Removing the app and revoking consent in Microsoft Entra ID ends TeamsPIM's access to your tenant. Cached Adaptive Card state expires on its own; subscription configuration is removed in line with our Privacy Policy and your agreement. |
|---|---|
| Deletion requests | Send deletion requests to contact@xertone.com and we will action them in line with our Privacy Policy. |
| Responsible disclosure | If you believe you've found a security vulnerability, email contact@xertone.com with "Security" in the subject. We review every report and will keep you informed. |
| Security reviews | Procurement or security questionnaire? We're glad to work through it — contact us and we'll provide the documentation your review needs. |
Bring Your Security Team to the Trial
Free trials include a permissions walkthrough and direct access to our team for security questions.