admins are unable to reset user´s passwords, how can I resolve it?

Paulo Ramos 0 Reputation points
2024-07-16T09:15:55.0133333+00:00

Hello dears,

I have 2 admin users that are not able to reset user´s password even though they have been granted the roles of helpdesk administrator/password administrator. After looking at the logs on Microsoft Entra ID>Audit Logs, I have seen the following error message:

Microsoft.Online.Administration.AccessDeniedException

Note: Those 2 admins were able to perform this task two months ago. Looks like something has changed since then.

anyone can help?

Thanks

Paulo Ramos

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,238 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,617 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Manu Philip 17,671 Reputation points MVP
    2024-07-16T09:40:00.3066667+00:00

    Hi,

    If PIM (Privileged Identity Mangement) has introduced recently, you might have to check the following article to extend their capabilities to change passwords

    Extend or renew Microsoft Entra role assignments in Privileged Identity Management


  2. Andy David - MVP 145.5K Reputation points MVP
    2024-07-16T10:12:49.0533333+00:00

  3. Yanhong Liu 5,140 Reputation points Microsoft Vendor
    2024-07-17T07:29:45.9733333+00:00

    Hello,

    Thank you for posting in Q&A forum.

    Based on the information provided, it seems like the two admin users are having issues with resetting passwords despite having the necessary roles. Here are a few suggestions:

    1. Check the Role Assignments: Ensure that the roles assigned to these users are still active and haven't expired. Sometimes, roles can be deactivated or expire without notice.
    2. Verify Permissions: Make sure that the permissions associated with the roles are correctly configured. Even if the users have the right roles, they might not have the necessary permissions if they are not set up correctly.
    3. Update Roles: If Privileged Identity Management (PIM) has been introduced recently, you might need to extend their capabilities to change passwords as suggested in the answer.
    4. Elevated Accounts: If the accounts they are trying to reset are elevated, they might need the privileged authentication admin role.
    5. Audit Logs: Since you have access to the audit logs, look for any changes made to these users' roles or permissions around the time they started experiencing this issue. This might give you a clue as to what has changed.

    I hope the information above is helpful.

    Best Regards,

    Yanhong Liu

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.