An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
If the organization Dev account is an Azure subscription or management group and access was lost, a Global Administrator in Microsoft Entra ID can elevate access and then re-grant permissions.
Use this path if a Global Administrator is available:
- Sign in to the Azure portal with a Global Administrator account for the tenant.
- Follow the guidance in “Elevate access to manage all Azure subscriptions and management groups” to elevate access. This allows the Global Administrator to see and manage all subscriptions and management groups in the tenant.
- After elevation, assign the required role (for example, Owner, Contributor, or a custom role) on the target subscription or management group to the appropriate user or group via Azure role-based access control (Azure RBAC).
- Once access is restored, the Global Administrator can remove the elevated access if no longer needed.
If no one in the organization has access or the only Global Administrator is locked out, the tenant’s Global Administrator (if any) or appropriate support contact must work with Microsoft support as described in the account-access troubleshooting guidance to regain control, and then follow the elevation steps above.
References: