Share via

Created Role (Authentication Administrator) Based Group and added member but Role is not working

Shrikant Bhagwat 146 Reputation points
2026-03-01T02:18:10.73+00:00

I created role (Authentication Administrator) based in Entra. Added Member But member can NOT perform assigned role.

2026-02-28_20-40-16

2026-02-28_21-02-43

When user ShrikantNAM login , the user can reset authentication method of some but not some

2026-02-28_21-12-38

2026-02-28_21-13-54

Global Admin Role can Change any user's Authentication Method.

Let us know

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Answer accepted by question author

  1. Marcin Policht 89,825 Reputation points MVP Volunteer Moderator
    2026-03-01T02:51:34.6833333+00:00

    As far as I can tell, the behavior you are seeing is consistent with the way privileged roles and the Authentication Administrator role work in Entra ID. The Authentication Administrator role allows a user to manage authentication methods like resetting passwords and MFA settings, but it has scope limitations. Specifically, an Authentication Administrator cannot manage authentication methods for users who are assigned certain privileged roles, such as Global Administrator, Privileged Role Administrator, or other highly privileged roles. This is a built-in safeguard to prevent elevation of privileges or circumvention of security controls.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    Was this answer helpful?

    1 person found this answer helpful.

Answer accepted by question author

  1. Huỳnh Ngọc Dương 75 Reputation points
    2026-03-01T15:32:19.8533333+00:00

    'Accepted Microsoft Entra ID

    Was this answer helpful?

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.