Releases: markorr321/PIM-Global
Release list
PIM-Global v3.1.0
🚀 New Version Released!
-
v2.0.0 – Full Lifecycle Management
-
Supports role activation and deactivation
-
Adds active role detection and filtering.
-
Enables multi-role operations (activate/deactivate multiple at once).
-
Adds interactive session mode without re-authentication.
-
Implements color-coded output, improved error handling, and real-time API sync.
PIM-Global v3.0.0
🚀 Overview
PIM-Global is a lightweight, secure desktop utility designed to streamline Entra ID Privileged Identity Management (PIM) role activation across global tenants.
This release introduces a standalone executable (PIM-Global.exe) that enables IT administrators and support personnel to easily:
✅ Authenticate via Microsoft.Graph with MSAL
✅ Activate eligible PIM roles in their assigned tenants
✅ View activation details such as role names and expiration
✅ Receive clear, color-coded feedback for MFA prompts, success messages, errors, and session states
✨ Key Features
⚡ No PowerShell Required – All functionality is wrapped in a native executable
🌍 Multi-Tenant Support – Designed for distributed IT teams across regions
🧠 MSAL Integration – Uses modern authentication with system browser fallback (embedded web view disabled for compatibility)
🎨 Colorized Output – Enhanced CLI feedback to guide the user through each step
🛠️ Built for Your Tenant – Configured for global use and any Entra ID tenant
🚫 Why No Embedded Web View?
Originally, this project aimed to use MSAL’s EmbeddedWebView for cleaner in-app authentication.
But here's the catch: MSAL requires a valid GUI window handle and message loop to host the embedded browser.
Since PIM-Global.exe is a portable C-based launcher running PowerShell in a headless console context, MSAL can't embed the browser — there’s no HWND or UI thread to attach to.
✅ Solution: Use -UseEmbeddedWebView:$false to launch the system browser, which ensures a smooth, secure login experience — even in non-GUI environments.
🖥️ System Requirements
Windows 10/11 (x64)
.NET Desktop Runtime 6.0+ (if applicable)
Entra ID account with eligible PIM roles
📦 Installation
Download PIM-Global.exe from the release below
Run as a standard user (no admin rights required)
Follow the interactive prompts
📝 Notes
This app is intended for internal distribution. Ensure your account meets role eligibility requirements in Entra PIM.
This script will automatically install the required PowerShell modules if they are not already present:
MSAL.PS for interactive login
Microsoft.Graph for role management
No administrative privileges are required.
However:
Internet access must be available
Script execution must be permitted
🧠 Example Usage
🟢 Run EXE
Launch the standalone executable and begin authentication.
👤 Select Your Account
Choose the Entra ID account with eligible roles.

🔑 Passkey Interaction
Respond to the passkey prompt using platform authentication.

📷 Scan QR Code
Complete sign-in using your mobile authenticator.

✅ MFA Confirmation
Confirm device trust and session authentication.

🎭 Role Retrieval
View available eligible roles from Microsoft Graph.

🧾 Selecting Your Role
Enter the number of the role you want to activate.

⏳ Role Duration
Choose how long to activate the role for (within allowed limits).

📝 Enter Justification
Provide a business reason for role activation.

🟖️ Role Activation Complete
See confirmation including role name and expiration timestamp.

🔧 Entra Global PIM Launcher – Build Summary
🔍 Technologies Used
-
PowerShell 7.5+
Handles login, Graph API connection, role selection, and activation. -
MSAL.NET (Microsoft.Identity.Client.dll)
-
Embedded DLLs enable secure interactive login with enforced MFA (acrs=c1) via system browser.
-
Microsoft Graph PowerShell SDK
Modules:Microsoft.Graph.Authentication
Microsoft.Graph
-
C# (.NET 6)
A lightweight launcher that:Extracts and runs the PowerShell script
Copies DLLs to temp runtime location
Launches pwsh.exe with env vars
Brings the console to foreground via Windows API
-
Windows API Interop
Uses user32.dll via P/Invoke to run SetForegroundWindow after login.
.NET Publish Options
PublishSingleFile=true
SelfContained=true
RuntimeIdentifier=win-x64**
PIM-Global v2.0.0
PIM-Global v2.0.0
Overview
PIM-Global is a lightweight, secure desktop utility designed to streamline Entra ID Privileged Identity Management (PIM) role activation across global tenants.
This release introduces a standalone executable (PIM-Global.exe) that enables IT administrators and support personnel to easily:
✅ Authenticate via Microsoft.Graph with MSAL
✅ Activate eligible PIM roles in their assigned tenants
✅ View activation details such as role names and expiration
✅ Receive clear, color-coded feedback for MFA prompts, success messages, errors, and session states
Key Features
⚡ No PowerShell Required – All functionality is wrapped in a native executable
🌍 Multi-Tenant Support – Designed for distributed IT teams across regions
🧠 MSAL Integration – Uses modern authentication with embedded web view disabled for compatibility
🎨 Colorized Output – Enhanced CLI feedback to guide the user through each step
🛠️ Built for Your Tenant – Configured for global use and any tenant
System Requirements
- Windows 10/11 (x64)
- .NET Desktop Runtime 6.0+ (if applicable)
- Entra ID account with eligible PIM roles
Installation
- Download
PIM-Global.exebelow - Run as a standard user (no admin rights needed)
- Follow the interactive prompts
Notes
This app is intended for internal distribution. Ensure your account meets the role eligibility requirements in Entra AD PIM.
This script will automatically install the required PowerShell modules if they are not already present:
MSAL.PSfor interactive loginMicrosoft.Graphfor role management
No administrative privileges are required. However:
- Internet access must be available
- Script execution must be permitted
🧠 Example
🟢 Run EXE
Launch the standalone executable and begin authentication.
👤 Select Your Account
Choose the Entra ID account with eligible roles.

🔑 Passkey Interaction
Respond to the passkey prompt using platform authentication.
📷 Scan QR Code
Complete the device sign-in by scanning the QR code with your mobile authenticator.
✅ MFA Confirmation
Verify the device connection and wait for session confirmation.
🎭 Role Retrieval
View your eligible PIM roles retrieved from Microsoft Graph.
🧾 Selecting Your Role
Enter the number corresponding to the role you want to activate.
⏳ Role Duration
Input your desired activation time within allowed limits.
📝 Enter Reason for Activation
Justify your request in compliance with PIM policy.
🟖️ Role Activation Complete
Receive confirmation including role name and expiration time.
Full Changelog: v1.0.0...v1.0.0
PIM-Global v1.0.0
PIM-Global v1.0.0
Overview
PIM-Global is a lightweight, secure desktop utility designed to streamline Entra ID Privileged Identity Management (PIM) role activation across global tenants.
This release introduces a standalone executable (PIM-Global.exe) that enables IT administrators and support personnel to easily:
✅ Authenticate via Microsoft.Graph with MSAL
✅ Activate eligible PIM roles in their assigned tenants
✅ View activation details such as role names and expiration
✅ Receive clear, color-coded feedback for MFA prompts, success messages, errors, and session states
Key Features
⚡ No PowerShell Required – All functionality is wrapped in a native executable
🌍 Multi-Tenant Support – Designed for distributed IT teams across regions
🧠 MSAL Integration – Uses modern authentication with embedded web view disabled for compatibility
🎨 Colorized Output – Enhanced CLI feedback to guide the user through each step
🛠️ Built for Your Tenant – Configured for global use and any tenant
System Requirements
- Windows 10/11 (x64)
- .NET Desktop Runtime 6.0+ (if applicable)
- Entra ID account with eligible PIM roles
Installation
- Download
PIM-Global.exebelow - Run as a standard user (no admin rights needed)
- Follow the interactive prompts
Notes
This app is intended for internal distribution. Ensure your account meets the role eligibility requirements in Entra AD PIM.
This script will automatically install the required PowerShell modules if they are not already present:
MSAL.PSfor interactive loginMicrosoft.Graphfor role management
No administrative privileges are required. However:
- Internet access must be available
- Script execution must be permitted
🧠 Example
🟢 Run EXE
Launch the standalone executable and begin authentication.
👤 Select Your Account
Choose the Entra ID account with eligible roles.

🔑 Passkey Interaction
Respond to the passkey prompt using platform authentication.
📷 Scan QR Code
Complete the device sign-in by scanning the QR code with your mobile authenticator.
✅ MFA Confirmation
Verify the device connection and wait for session confirmation.
🎭 Role Retrieval
View your eligible PIM roles retrieved from Microsoft Graph.
🧾 Selecting Your Role
Enter the number corresponding to the role you want to activate.
⏳ Role Duration
Input your desired activation time within allowed limits.
📝 Enter Reason for Activation
Justify your request in compliance with PIM policy.
🟖️ Role Activation Complete
Receive confirmation including role name and expiration time.
Full Changelog: v1.0.0...v1.0.0