A Windows desktop tool that configures PIM settings for many Entra ID roles and PIM-enabled groups at once. Pick the roles, set the policy once, preview the changes and apply, instead of editing every role by hand in the portal.
Configure PIM for many roles at once, without the repetitive clicking. Select the Entra ID roles and PIM-enabled groups you want to change, define the settings once, preview every change and apply them all in one go.
Apply the same PIM settings to many roles: Global Administrator, User Administrator and more.
Configure the member and owner settings of your PIM-enabled groups.
See every change as Current → New value, grouped by category and role.
Max duration, MFA or Conditional Access authentication context, justification, ticket info and approval.
Permanent or expiring eligible/active assignments, MFA and justification on active assignment.
Control notifications to admins, assignees and approvers for assignments and activations.
Get tool.zip from the latest release.
Right-click tool.zip → Extract All… to a folder on your PC.
Open the extracted tool folder and run PIMSettings Manager.exe.
# Download the latest release Invoke-WebRequest -Uri "https://github.com/Appelcloud/PimSettingsManager/releases/latest/download/tool.zip" -OutFile "$env:USERPROFILE\Downloads\tool.zip" # Extract the tool Expand-Archive -Path "$env:USERPROFILE\Downloads\tool.zip" -DestinationPath "$env:USERPROFILE\PIMSettingsManager" -Force # Run PIMSettings Manager Get-ChildItem "$env:USERPROFILE\PIMSettingsManager" -Recurse -Filter "PIMSettings Manager.exe" | Select-Object -First 1 | Start-Process
winget install Microsoft.DotNet.DesktopRuntime.8