Can't remove last role assignment to Privileged Role Administrator in Azure

Raitis Neitāls 51 Reputation points
2022-05-18T10:39:38.053+00:00

Hello!

As Global Administrator why i can't remove last admin assignment to Privileged Role Administrator role?

Response from Azure i am receiving is: "Removing role assignment failed. Cannot delete the last admin assignment."

Is this set up like that by default for all admin Roles?

Thanks in advance!

Microsoft Entra
{count} votes

Accepted answer
  1. Shweta Mathur 27,141 Reputation points Microsoft Employee
    2022-05-19T11:16:22.337+00:00

    Hi @Anonymous ,

    Thanks for reaching out.

    I understand you are trying to delete all the role assignments to Privileged Role Administrator and getting error while deleting last assignment.

    The error you are getting is expected as you can't remove last assignment from Privileged Role Administrator. This role manages Azure AD PIM and grants the ability to manage assignments for all Azure AD roles including the Global Administrator role.

    The Azure AD Privileged Identity Management (PIM) service also allows Privileged role administrators to make permanent admin role assignments.

    This has only been setup like that only for Privileged Role Administrator, not for all the administrator roles.

    Hope this will help.

    Thanks,
    Shweta

    -----------------------------------

    Please remember to "Accept Answer" if answer helped you.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful