QuestionQ4

Manage identity, access, and governance

You have two management groups, MG1 and MG2, which contain multiple Azure subscriptions. The subscriptions are associated with a Microsoft Entra tenant.

You have a user named User1 and a global administrator named Admin1.

You learn that User1 created an Azure subscription named Sub1 under the MG2 management group and is its only owner.

You need to ensure that Admin1 can remove User1's Owner role on Sub1.

What should you do first?

Explanation

A Microsoft Entra Global Administrator does not automatically have Azure RBAC access to every subscription. Enabling Access management for Azure resources elevates the signed-in Global Administrator by assigning the Azure User Access Administrator role at the root scope. That role permits management of role assignments across subscriptions and management groups in the tenant, including removal of User1’s Owner assignment on Sub1.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!