Azure PIM with role Azure AD joined administrator approval can't elevate permissions

Diego Ramírez 60 Reputation points
2023-07-14T11:53:35.95+00:00

We have a user who requests through PIM a request to receive the Azure AD joined administrator role on his PC (AD joined) to format a pendrive.

We see that despite having the administrator role assigned, he is not allowed to format the flash drive, the screen displays the message "The requested operation requires elevation".

I am supposed to be able to do it with the Azure AD joined administrator role. What could go wrong then?

Regards.

Microsoft Security | Microsoft Entra | Other
{count} votes

1 answer

Sort by: Most helpful
  1. JamesTran-MSFT 36,911 Reputation points Microsoft Employee Moderator
    2023-07-18T21:51:06.6566667+00:00

    @Diego Ramírez

    Thank you for your post and I apologize for the delayed response!

    Error Message:

    The requested operation requires elevation

    I understand that one of your user's elevated their permissions through PIM in order to act as an Azure AD admin to format a pen/flash drive, but they're running into the above error message. To hopefully help point you in the right direction or resolve your issue, I'll share my findings below.


    Findings:

    When it comes to PIM and managing the device administrator role(s), please keep in mind that updating the device administrator role doesn't necessarily have an immediate impact on the affected users. On devices where a user is already signed into, the privilege elevation takes place when both the below actions happen:

    • Up to 4 hours have passed for Azure AD to issue a new Primary Refresh Token with the appropriate privileges.
    • User signs out and signs back in, not lock/unlock, to refresh their profile.

    It could also be possible that the user needs to open/format the flash drive as a Local Administrator. To do this, they can right-click on the drive and select Run as administrator, or open Properties select the compatibility tab and check the box shown before Run this Program as an administrator.

    User's image


    Additional Links:

    I hope this helps!

    If you have any other questions or are still having issues, please let me know. Thank you for your time and patience throughout this issue.


    If the information helped address your question, please Accept the answer. This will help us and also improve searchability for others in the community who might be researching similar information.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.