AzureAD: Authentication Administrator incorrectly granted access to delete users

IT-GA 21 Reputation points
2022-08-01T14:30:37.203+00:00

I have assigned a user the Authentication Administrator role within AzureAD.

They are not able to delete users according to the role permissions and when accessing aad.portal.azure.com they are unable to delete users. This is the expected behaviour.

226873-authadmin2.png

However, when accessing 'Active Users' via admin.microsoft.com they are able to delete users. I have deleted a test user and the operation completed successfully.

Are the permissions for this portal configured elsewhere? It seems like an oversight that these users would be able to delete user accounts without being given the necessary permission.

226780-authadmin.png

Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

Accepted answer
  1. Shweta Mathur 30,296 Reputation points Microsoft Employee Moderator
    2022-08-02T13:29:51.927+00:00

    Hi @IT-GA ,

    Thanks for reaching out.

    I understand you are able to delete users with least administrative role Authenticator Administrator via admin.microsoft.com but delete option is disabled in aad.portal.azure.com.

    I tried to repro the scenario in both the portals in my lab. Both the portals are showing the same behavior and allow to delete the users with Authenticator Administrator role.

    In case of aad.portal.azure.com, you need to select the user you want to delete to enable the delete button.

    227281-image.png

    Authentication Administrator allow the action to delete the users from both the portals which is not documented properly here.

    However, I checked the actions of Authentication Administrator in the portal which has permission to delete the users.

    227198-image.png

    I will check this internally with the content team and will update the documentation.

    Hope this will help.

    Thanks,
    Shweta

    ----------------------------

    Please remember to "Accept Answer" if answer helped you.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.