Locked out of directory I am an Owner of

Emile Kratiroff 20 Reputation points
2024-04-30T06:46:22.09+00:00

Hello,

A friend invited me to their Azure Entra ID as a guest user, and set me as a member of the admin group that has owner privileges.

I was able to log in for 10 days, created resources (including an Azure Databricks cluster that no one can access now). But somehow lost access to the directory.

In fact, I do not see their directory when I click "switch directory" when logged in to the Azure portal.

They triple checked, my user is still active on their Entra ID, and I am still part of the admin group.

Any ideas what we did wrong?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,994 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,846 questions
0 comments No comments
{count} votes

Accepted answer
  1. Babafemi Bulugbe 2,190 Reputation points MVP
    2024-04-30T10:29:15.3833333+00:00

    Hello Emile Kratiroff,

    Thank you for raising your question in the Microsoft Q&A Community.

    I understand you are not able to access the directory you were invited to.

    Firstly, check if you have a dual account (if your account has a work or school account and also a personal account). If you logged in to a different one other that the one you use to authenticate with, then this might be a reason why you are not seeing the tenant under the switch feature

    User's image

    To check this, open an Inprivate or Incognito tab and try accessing the portal. If your account is dual, you will have the same as in the screenshot above.

    Secondly, get the tenant id of the Organization and force the authentication if the first rule doesnt apply to you. Authenticate by going to portal.azure.co/tenantid and see if you are able to authenticate.

    If the above doesnt work, have them reset the invitation

    User's image

    Please note that if there is a need to allow someone else have access to those resources, the Global Admin in the tenant can elevate him or herself and assign a role to his or her account after the elevation. Elevating a Global Admin account will give access to the Global Admin on all the Subscriptions and Resources within the tenant.

    Follow this link to learn more about elevation https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin?tabs=azure-portal

    Let me know if further assistance is needed.

    Babafemi

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Babafemi Bulugbe 2,190 Reputation points MVP
    2024-04-30T10:29:40.2066667+00:00

    Hello Emile Kratiroff,

    Thank you for raising your question in the Microsoft Q&A Community.

    I understand you are not able to access the directory you were invited to.

    Firstly, check if you have a dual account (if your account has a work or school account and also a personal account). If you logged in to a different one other that the one you use to authenticate with, then this might be a reason why you are not seeing the tenant under the switch feature

    User's image To check this, open an Inprivate or Incognito tab and try accessing the portal. If your account is dual, you will have the same as in the screenshot above.

    Secondly, get the tenant id of the Organization and force the authentication if the first rule doesnt apply to you. Authenticate by going to portal.azure.co/tenantid and see if you are able to authenticate.

    If the above doesnt work, have them reset the invitation

    User's image Please note that if there is a need to allow someone else have access to those resources, the Global Admin in the tenant can elevate him or herself and assign a role to his or her account after the elevation. Elevating a Global Admin account will give access to the Global Admin on all the Subscriptions and Resources within the tenant.

    Follow this link to learn more about elevation https://learn.microsoft.com/en-us/azure/role-based-access-control/elevate-access-global-admin?tabs=azure-portal

    Let me know if further assistance is needed.

    Babafemi

    0 comments No comments