Group expiration page is accesible with direct role assigment for user

j prasad 31 Reputation points
2023-08-25T00:37:24.7133333+00:00

When we assign global admin role to the user he can access group expiration .But,an Azure AD global admin role that is granted via a group they cannot access the Group Expriation settings. But if they are directly assigned the Azure AD role they can see the settings. 

Microsoft Security | Microsoft Entra | Microsoft Entra ID

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

Answer accepted by question author
Shweta Mathur 30,471 Reputation points Microsoft Employee Moderator
2023-08-28T06:29:28.3933333+00:00

Hi @j prasad ,

Thanks for reaching out.

Your understanding is correct here.

If a user is assigned the Global Administrator role directly, they will have access to the Group Expiration settings. However, if the Global Administrator role is granted via a group, they will not have access to the Group Expiration settings**.**

This is because group-based permissions are evaluated differently than direct permissions. In the case of direct permissions, the user is granted the permission directly, without any intermediary group**.** This means that the user has permission regardless of any group membership.

In the case of group-based permissions, the user is granted permission through membership in a group**.** This means that the user only has permission if they are a member of the group that has been granted the permission.

When a user has both direct and group-based permissions, the more restrictive permission takes precedence.

Hope this will help.

Thanks,

Shweta


Please remember to "Accept Answer" if answer helped you.

Was this answer helpful?

2 people found this answer helpful.

0 additional answers

Sort by: Most helpful