Custom Role in EntraID

Roger Roger 7,306 Reputation points
2025-06-25T05:32:10.14+00:00

Hi All,

I want to create a custom role to grant a few admins the ability to enable MFA for guest users.

In the Authentication Methods blade, these admins should be able to perform the following actions for guest users:

Require re-registration for multi-factor authentication

Revoke multi-factor authentication sessions

I also want to manage this role assignment through Privileged Identity Management (PIM). Please guide me on how to create this custom role.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Answer accepted by question author
  1. Gudivada Adi Navya Sri 21,075 Reputation points Moderator
    2025-06-25T11:19:08.58+00:00

    Hi Roger Roger

    Custom roles in Microsoft Entra ID support a defined set of granular permissions for user management, but not all actions are available for custom roles. The ability to require re-registration for MFA and revoke MFA sessions is not currently exposed as a customizable permission for custom roles. These actions are included in the built-in Authentication Administrator or Privileged Authentication Administrator roles.User's image

    I would appreciate it if you could share your feedback on our Azure feedback portal: https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789

    As of now, you can't create a custom role for your requirement; you need to use the built-in roles.

    To configure PIM for Entra roles, you can follow this document: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-how-to-add-role-to-userHope this helps. Do let us know if you any further queries.

    Please remember to "Accept Answer" if answer helped you. This will help us as well as others in the community who might be researching similar questions.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.