An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
Hello @Siu, Steven
The disabled Add role assignment button indicates that your account doesn't currently have permission to create Azure RBAC role assignments at that management group scope.
The Security Administrator role you're seeing is a Microsoft Entra role. Microsoft Entra roles and Azure RBAC roles are separate, so Security Administrator doesn't give you Microsoft.Authorization/roleAssignments/write on Azure management groups.
To assign Owner or another Azure role at the management-group level, the account performing the assignment needs an Azure RBAC role containing that permission, such as Role-Based Access Control Administrator or User Access Administrator, at that management group or an inherited parent scope.
If nobody currently has sufficient Azure RBAC access, a Global Administrator in Microsoft Entra ID can recover access using Microsoft's documented elevation procedure:
- Sign in as a Global Administrator. If the role is managed through PIM, activate it first.
- Go to Microsoft Entra ID → Properties.
- Set Access management for Azure resources to Yes and save.
- Sign out and back in.
This temporarily assigns that Global Administrator the Azure User Access Administrator role at root scope (/), allowing the administrator to assign Azure RBAC roles across the tenant's subscriptions and management groups.
You can verify the elevation with Azure CLI:
az role assignment list \
--role "User Access Administrator" \
--scope "/" \
--output table
Then return to: Management Groups → <your management group> → Access control (IAM)
and the administrator should be able to create the required role assignment.
Don't leave the Global Administrator elevated permanently. I recommend using elevated access to restore the appropriate Azure RBAC administration path, then setting Access management for Azure resources back to No. That removes the temporary User Access Administrator assignment at /.
If a Global Administrator has already performed this elevation and Add role assignment is still disabled, then check the effective Azure role assignments and any deny assignments at the management-group/root scope before making further changes.
References:
Elevate access to manage Azure subscriptions and management groups
Assign Azure roles using the Azure portal
Azure roles vs. Microsoft Entra roles
Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.