How to create policy to deny direct user assignment to Privileged roles instead assigning roles via groups

curious7 251 Reputation points
2024-08-05T12:00:59.8966667+00:00

I need to create a policy to deny direct user assignment to Entra privileged roles and force them to use groups instead for privileged role assignments.

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
911 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,068 questions
0 comments No comments
{count} votes

Accepted answer
  1. Vasil Michev 107.3K Reputation points MVP
    2024-08-06T15:52:25.0333333+00:00

    There are no such controls within Entra ID, you will have to create and use your own workflow outside of Entra's admin tools.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.