Skip to content

Releases: markorr321/PIM-Global

PIM-Global v3.1.0

Choose a tag to compare

@markorr321 markorr321 released this 26 Jul 07:45
be65a1b

🚀 New Version Released!

  • v2.0.0 – Full Lifecycle Management

  • Supports role activation and deactivation

  • Adds active role detection and filtering.

  • Enables multi-role operations (activate/deactivate multiple at once).

  • Adds interactive session mode without re-authentication.

  • Implements color-coded output, improved error handling, and real-time API sync.

PIM-Global v3.0.0

Choose a tag to compare

@markorr321 markorr321 released this 15 Jul 14:12
bdd6454

🚀 Overview

PIM-Global is a lightweight, secure desktop utility designed to streamline Entra ID Privileged Identity Management (PIM) role activation across global tenants.

This release introduces a standalone executable (PIM-Global.exe) that enables IT administrators and support personnel to easily:

✅ Authenticate via Microsoft.Graph with MSAL

✅ Activate eligible PIM roles in their assigned tenants

✅ View activation details such as role names and expiration

✅ Receive clear, color-coded feedback for MFA prompts, success messages, errors, and session states

✨ Key Features
⚡ No PowerShell Required – All functionality is wrapped in a native executable

🌍 Multi-Tenant Support – Designed for distributed IT teams across regions

🧠 MSAL Integration – Uses modern authentication with system browser fallback (embedded web view disabled for compatibility)

🎨 Colorized Output – Enhanced CLI feedback to guide the user through each step

🛠️ Built for Your Tenant – Configured for global use and any Entra ID tenant

🚫 Why No Embedded Web View?
Originally, this project aimed to use MSAL’s EmbeddedWebView for cleaner in-app authentication.
But here's the catch: MSAL requires a valid GUI window handle and message loop to host the embedded browser.

Since PIM-Global.exe is a portable C-based launcher running PowerShell in a headless console context, MSAL can't embed the browser — there’s no HWND or UI thread to attach to.

✅ Solution: Use -UseEmbeddedWebView:$false to launch the system browser, which ensures a smooth, secure login experience — even in non-GUI environments.

🖥️ System Requirements
Windows 10/11 (x64)

.NET Desktop Runtime 6.0+ (if applicable)

Entra ID account with eligible PIM roles

📦 Installation
Download PIM-Global.exe from the release below

Run as a standard user (no admin rights required)

Follow the interactive prompts

📝 Notes
This app is intended for internal distribution. Ensure your account meets role eligibility requirements in Entra PIM.

This script will automatically install the required PowerShell modules if they are not already present:

MSAL.PS for interactive login

Microsoft.Graph for role management

No administrative privileges are required.
However:

Internet access must be available

Script execution must be permitted

🧠 Example Usage
🟢 Run EXE

Launch the standalone executable and begin authentication.

👤 Select Your Account
Choose the Entra ID account with eligible roles.
PIM - Select Account

🔑 Passkey Interaction
Respond to the passkey prompt using platform authentication.
PIM - SignIn with Passkey

📷 Scan QR Code
Complete sign-in using your mobile authenticator.
PIM - QR Code Scan

✅ MFA Confirmation
Confirm device trust and session authentication.
PIM - Device Connected Notification

🎭 Role Retrieval
View available eligible roles from Microsoft Graph.
PIM - Role Retrieval

🧾 Selecting Your Role
Enter the number of the role you want to activate.
PIM - Role Selection

⏳ Role Duration
Choose how long to activate the role for (within allowed limits).
PIM - Duration Entry

📝 Enter Justification
Provide a business reason for role activation.
PIM - Enter Justification

🟖️ Role Activation Complete
See confirmation including role name and expiration timestamp.
PIM - Final

🔧 Entra Global PIM Launcher – Build Summary
🔍 Technologies Used

  • PowerShell 7.5+
    Handles login, Graph API connection, role selection, and activation.

  • MSAL.NET (Microsoft.Identity.Client.dll)

  • Embedded DLLs enable secure interactive login with enforced MFA (acrs=c1) via system browser.

  • Microsoft Graph PowerShell SDK
    Modules:

    Microsoft.Graph.Authentication

    Microsoft.Graph

  • C# (.NET 6)
    A lightweight launcher that:

    Extracts and runs the PowerShell script

    Copies DLLs to temp runtime location

    Launches pwsh.exe with env vars

    Brings the console to foreground via Windows API

  • Windows API Interop
    Uses user32.dll via P/Invoke to run SetForegroundWindow after login.

.NET Publish Options

PublishSingleFile=true

SelfContained=true

RuntimeIdentifier=win-x64**

PIM-Global v2.0.0

Choose a tag to compare

@markorr321 markorr321 released this 15 Jul 14:09
bdd6454

PIM-Global v2.0.0

Overview

PIM-Global is a lightweight, secure desktop utility designed to streamline Entra ID Privileged Identity Management (PIM) role activation across global tenants.

This release introduces a standalone executable (PIM-Global.exe) that enables IT administrators and support personnel to easily:

✅ Authenticate via Microsoft.Graph with MSAL
✅ Activate eligible PIM roles in their assigned tenants
✅ View activation details such as role names and expiration
✅ Receive clear, color-coded feedback for MFA prompts, success messages, errors, and session states


Key Features

⚡ No PowerShell Required – All functionality is wrapped in a native executable
🌍 Multi-Tenant Support – Designed for distributed IT teams across regions
🧠 MSAL Integration – Uses modern authentication with embedded web view disabled for compatibility
🎨 Colorized Output – Enhanced CLI feedback to guide the user through each step
🛠️ Built for Your Tenant – Configured for global use and any tenant


System Requirements

  • Windows 10/11 (x64)
  • .NET Desktop Runtime 6.0+ (if applicable)
  • Entra ID account with eligible PIM roles

Installation

  1. Download PIM-Global.exe below
  2. Run as a standard user (no admin rights needed)
  3. Follow the interactive prompts

Notes

This app is intended for internal distribution. Ensure your account meets the role eligibility requirements in Entra AD PIM.

This script will automatically install the required PowerShell modules if they are not already present:

  • MSAL.PS for interactive login
  • Microsoft.Graph for role management

No administrative privileges are required. However:

  • Internet access must be available
  • Script execution must be permitted

🧠 Example

🟢 Run EXE

Launch the standalone executable and begin authentication.

👤 Select Your Account

Choose the Entra ID account with eligible roles.
PIM - Select Account

🔑 Passkey Interaction

Respond to the passkey prompt using platform authentication.

PIM - SingIn with Passkey

📷 Scan QR Code

Complete the device sign-in by scanning the QR code with your mobile authenticator.

PIM - QR Code Scan

✅ MFA Confirmation

Verify the device connection and wait for session confirmation.

PIM - Device Connected Notification

🎭 Role Retrieval

View your eligible PIM roles retrieved from Microsoft Graph.

PIM - Role Retrieval

🧾 Selecting Your Role

Enter the number corresponding to the role you want to activate.

PIM - Role Selection

⏳ Role Duration

Input your desired activation time within allowed limits.

PIM - Duration Entry

📝 Enter Reason for Activation

Justify your request in compliance with PIM policy.

PIM - Enter Justification

🟖️ Role Activation Complete

Receive confirmation including role name and expiration time.

PIM - Final

Full Changelog: v1.0.0...v1.0.0

PIM-Global v1.0.0

Choose a tag to compare

@markorr321 markorr321 released this 15 Jul 12:28
a045714

PIM-Global v1.0.0

Overview

PIM-Global is a lightweight, secure desktop utility designed to streamline Entra ID Privileged Identity Management (PIM) role activation across global tenants.

This release introduces a standalone executable (PIM-Global.exe) that enables IT administrators and support personnel to easily:

✅ Authenticate via Microsoft.Graph with MSAL
✅ Activate eligible PIM roles in their assigned tenants
✅ View activation details such as role names and expiration
✅ Receive clear, color-coded feedback for MFA prompts, success messages, errors, and session states


Key Features

⚡ No PowerShell Required – All functionality is wrapped in a native executable
🌍 Multi-Tenant Support – Designed for distributed IT teams across regions
🧠 MSAL Integration – Uses modern authentication with embedded web view disabled for compatibility
🎨 Colorized Output – Enhanced CLI feedback to guide the user through each step
🛠️ Built for Your Tenant – Configured for global use and any tenant


System Requirements

  • Windows 10/11 (x64)
  • .NET Desktop Runtime 6.0+ (if applicable)
  • Entra ID account with eligible PIM roles

Installation

  1. Download PIM-Global.exe below
  2. Run as a standard user (no admin rights needed)
  3. Follow the interactive prompts

Notes

This app is intended for internal distribution. Ensure your account meets the role eligibility requirements in Entra AD PIM.

This script will automatically install the required PowerShell modules if they are not already present:

  • MSAL.PS for interactive login
  • Microsoft.Graph for role management

No administrative privileges are required. However:

  • Internet access must be available
  • Script execution must be permitted

🧠 Example

🟢 Run EXE

Launch the standalone executable and begin authentication.

👤 Select Your Account

Choose the Entra ID account with eligible roles.
PIM - Select Account

🔑 Passkey Interaction

Respond to the passkey prompt using platform authentication.

PIM - SingIn with Passkey

📷 Scan QR Code

Complete the device sign-in by scanning the QR code with your mobile authenticator.

PIM - QR Code Scan

✅ MFA Confirmation

Verify the device connection and wait for session confirmation.

PIM - Device Connected Notification

🎭 Role Retrieval

View your eligible PIM roles retrieved from Microsoft Graph.

PIM - Role Retrieval

🧾 Selecting Your Role

Enter the number corresponding to the role you want to activate.

PIM - Role Selection

⏳ Role Duration

Input your desired activation time within allowed limits.

PIM - Duration Entry

📝 Enter Reason for Activation

Justify your request in compliance with PIM policy.

PIM - Enter Justification

🟖️ Role Activation Complete

Receive confirmation including role name and expiration time.

PIM - Final

Full Changelog: v1.0.0...v1.0.0