Overview
Azure PIM and Entra role management in your browser
Privly puts Microsoft Entra ID and Azure Privileged Identity Management (PIM) in your browser toolbar. Activate eligible roles, handle approvals, and watch the clock on active access, without opening the Azure portal. Elevating through PIM normally costs you a portal tab, a handful of clicks, and no easy way to tell how much time you have left. Privly makes it one click and a visible countdown. WHAT YOU CAN DO - Activate and deactivate eligible Entra directory roles, PIM-enabled groups (member or owner), and Azure resource roles at any scope: management group, subscription, resource group, or individual resource - Approve or deny requests where you are the approver, and cancel your own pending requests - Track active assignments with live countdown timers, progress bars, and a toolbar badge showing the time left on the soonest-expiring activation - Get notified before an activation expires (configurable lead time) and again when it expires, each with its own sound - Search and filter across every role, group, and subscription you hold WORKS THE WAY YOUR ORGANIZATION DOES - Enforces your PIM policies in the form before you submit: maximum duration, justification, ticket number, and approval requirements - Handles step-up authentication inline, including MFA and Conditional Access authentication contexts - Signs in multiple accounts across multiple tenants at the same time, with instant switching between them - Optionally reloads open Microsoft admin portal tabs after activation so new permissions take effect right away - Never changes tenant configuration. No policy edits, no server-side agent, no standing permissions. Privly calls the same Microsoft Graph and ARM APIs the portal uses, on your behalf, with only the delegated scopes your admin consents to PRIVATE BY DESIGN - Everything stays on your device in browser storage. There is no Privly backend, no analytics, and no telemetry - Tokens come straight from Microsoft over the standard OAuth 2.0 authorization code flow with PKCE. Nothing is proxied through a third party - The built-in diagnostic log is redacted before anything is written: UPNs masked, GUIDs shortened, justification and ticket text never recorded. Disable or clear it at any time - Every permission Privly asks for is documented in plain language, with what it does and why it is needed. Nothing is requested that is not explained. The full breakdown is in the support center linked from this listing OPEN SOURCE Privly is licensed under the GNU General Public License v3.0 and the full source is published on GitHub, so your security team can read exactly what it does before anyone installs it: github.com/TriPointLabs/Privly GETTING STARTED 1. Pin Privly and sign in with your work account 2. Review your eligible roles, groups, and Azure scopes 3. Activate with the duration and justification your policy requires Privly needs an admin-consented Entra app registration in your tenant. An admin consent link is on the sign-in page, so your Entra administrator can approve it in about a minute. SOVEREIGN CLOUD: WE ARE LOOKING FOR A PARTNER Privly's sign-in flow already performs OpenID Connect cloud discovery and resolves the correct login, Graph, and ARM endpoints for Microsoft's sovereign clouds. The plumbing is there, but we will not claim GCC High or DoD support until it has been validated against a real sovereign tenant, and those are not something you can sign up for. If your organization runs in one and wants Privly there, we would love to partner with you. SUPPORT Questions, bugs, feature requests, and the full permission breakdown are all in the help center. Use the support link on this listing to get there.
0 out of 5No ratings
Details
- Version2.4.3
- UpdatedAugust 19, 2026
- Size518KiB
- LanguagesEnglish
- DeveloperTriPoint Labs, LLCWebsite
6 Eagle Ln Fairport, NY 14450-3310 USEmail
support@tripointlabs.comPhone
+1 585-414-8751 - TraderThis developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
- D-U-N-S118803374
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, please open this page on your desktop browser