
A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.
A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.
Before using azpim, ensure you have:
# Install Azure CLI (if not installed)
# See: https://docs.microsoft.com/en-us/cli/azure/install-azure-cli
# Login to Azure
az login
# Verify you're logged in
az account show
# Using npm
npm install -g azpim
# Using pnpm
pnpm add -g azpim
# Using yarn
yarn global add azpim
After installation, the azpim command will be available globally.
If you previously used azp-cli, your presets are stored in ~/.config/azp-cli/ (or %APPDATA%\azp-cli\ on Windows). To migrate:
presets.json to the new location: ~/.config/azpim/ (or %APPDATA%\azpim\)npm uninstall -g azp-cli# Clone the repository
git clone https://github.com/tapanmeena/azpim.git
cd azpim
# Install dependencies
pnpm install
# Build the project
pnpm build
# Link globally for development
npm link
# After global installation
azpim
# Or with specific commands
azpim activate
azpim deactivate
azpim preset list
azpim update
# Development mode (from source)
pnpm dev
| Command | Alias | Description |
|---|---|---|
activate | a | Activate a role in Azure PIM (default) |
deactivate | d | Deactivate a role in Azure PIM |
preset | - | Manage reusable presets |
favorites | fav | Manage favorite subscriptions |
check-update | update, upgrade | Check for a newer version |
help | - | Display help information |
Global Flags:
--debug - Enable debug logging--version - Show version number| Command | Description |
|---|---|
preset list | List all available presets |
preset show | Show details of a specific preset |
preset add | Add a new preset (interactive wizard) |
preset edit | Edit an existing preset (interactive wizard) |
preset remove | Remove a preset |
| Command | Description |
|---|---|
favorites list | List all favorite subscriptions |
favorites add | Add a subscription to favorites |
favorites remove | Remove a subscription from favorites |
favorites clear | Clear all favorites |
favorites export | Export favorites to a file |
favorites import | Import favorites from a file |
favorites refresh | Refresh the subscription cache |
You can check if a newer version is available:
azpim update
# alias
azpim upgrade
Notes:
azpim update exits with code 0 when up-to-date, 2 when an update is available, and 1 on error.--check-only - Only check and print status without showing upgrade instructions.--output json returns a structured response suitable for scripts.azpim activate and azpim deactivate will also show a short "update available" hint (text mode only) at most once per day.AZPIM_NO_UPDATE_NOTIFIER=1 (or AZPIM_DISABLE_UPDATE_CHECK=1).The update-check cache is stored alongside presets in your config directory:
~/.config/azpim/update-check.json (or $XDG_CONFIG_HOME/azpim/update-check.json)%APPDATA%\azpim\update-check.jsonUse flags to activate or deactivate PIM roles directly without going through the interactive menu, perfect for scripting and CI/CD workflows.
# Activate a single role by name (non-interactive)
azpim activate --non-interactive --yes \
--subscription-id <SUBSCRIPTION_GUID> \
--role-name "Owner" \
--duration-hours 2 \
--justification "Break-glass for incident" \
--output json
# Activate multiple roles (repeat --role-name)
azpim activate --non-interactive --yes \
--subscription-id <SUBSCRIPTION_GUID> \
--role-name "Contributor" \
--role-name "User Access Administrator"
# If a role name matches multiple eligible roles (different scopes),
# --non-interactive will error unless you explicitly allow activating all matches
azpim activate --non-interactive --yes \
--subscription-id <SUBSCRIPTION_GUID> \
--role-name "Contributor" \
--allow-multiple
# Preview what would happen without submitting requests
azpim activate --non-interactive --dry-run \
--subscription-id <SUBSCRIPTION_GUID> \
--role-name "Contributor" \
--output json
# Deactivate specific roles
azpim deactivate --non-interactive --yes \
--subscription-id <SUBSCRIPTION_GUID> \
--role-name "Owner" \
--justification "Task completed"
# Deactivate across all subscriptions (omit subscription-id)
azpim deactivate --non-interactive --yes \
--role-name "Contributor" \
--allow-multiple
Common flags (activate/deactivate):
--non-interactive - Disable interactive prompts-y, --yes - Skip confirmation prompts--subscription-id <id> - Target subscription (optional for deactivate)--role-name <name> - Role name(s) to target (can be repeated)--allow-multiple - Allow multiple role matches--dry-run - Preview without submitting--output <text|json> - Output format (default: text)--quiet - Suppress non-essential outputActivation-specific:
--duration-hours <n> - Duration (1-8 hours, default varies by role)--justification <text> - Justification for activationDeactivation-specific: