949 questions with Azure Role-based access control tags

Sort by: Updated
2 answers

How to Create a Custom Role for Azure Key Vault That Allows Writing Secrets Without Read Access (RBAC)

I'm trying to implement least privilege access to Azure Key Vault using the RBAC permission model, as recommended by Microsoft. My objective is to assign an Entra ID group a role that: Allows writing or updating secrets (e.g. set operations) Allows…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-03T18:03:50.1466667+00:00
Jonathan Lafleur 0 Reputation points
commented 2025-06-18T16:59:24.16+00:00
Kancharla Saiteja 5,080 Reputation points Microsoft External Staff Moderator
2 answers One of the answers was accepted by the question author.

How can I identify if these service principles are related to which resources ?

I have deleted Azure Resources group along with all resources manually. Now I can see 2 Service principal left behind. How can I identify if these service principles are related to any other resource which may still exist? If I delete these service…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-14T07:49:47.6866667+00:00
Satish Kumar (EXT-Nokia) 0 Reputation points
accepted 2025-06-18T08:14:46.51+00:00
Satish Kumar (EXT-Nokia) 0 Reputation points
1 answer

Is there any way of extending token life time in Microsoft External Entra?

Hello, I'm currently working with Microsoft Entra External ID, and I would like to know if there is any supported way to extend the lifetime of issued access tokens. By default, access tokens seem to expire after 1 hour, which is expected. However,…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-17T12:34:09.3266667+00:00
Mikail Ceran 20 Reputation points
commented 2025-06-18T07:40:03.8333333+00:00
Mikail Ceran 20 Reputation points
1 answer

Unable to Access Azure RBAC PIM Approval Data via App-Only Token

I'm trying to retrieve approvals using the management.azure.com API, but the endpoint requires a user token instead of an app token. However, the Microsoft Graph API returns PIM request approvals successfully using an app token. I want getting approvals…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-15T16:58:01.58+00:00
Abdulrahman Elheyb 0 Reputation points
commented 2025-06-17T18:35:31.0833333+00:00
Abdulrahman Elheyb 0 Reputation points
0 answers

Can't remove last role assignment to Privileged Role Administrator in Azure

When trying to remove the last privileged role from a subscription I'm getting the following Error - {"Error":{"Message":"Cannot delete the last RBAC admin…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-17T07:15:36.6366667+00:00
Super Admin 0 Reputation points
commented 2025-06-17T13:55:35.9533333+00:00
Raja Pothuraju 22,980 Reputation points Microsoft External Staff Moderator
2 answers One of the answers was accepted by the question author.

How to get v2 token

Hi team, I'm trying to get the token based on the 'az login' I did manually in cmd before running the script: class TokenProvider: def __init__(self): self.credential = AzureCliCredential() self.cached_token = None …

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-05-28T13:59:15.2233333+00:00
Maria Dąbrowiecka 80 Reputation points
commented 2025-06-17T13:44:34.3133333+00:00
Maria Dąbrowiecka 80 Reputation points
2 answers One of the answers was accepted by the question author.

Remove old tenant from personal account for azure subscription for Azure Boot Camp

Hello, I am writing to you from my @microsoft account. I activated a visual studio enterprise subscription on my personal account for the Azure Boot Camp, but I get some tenant permissions errors from a very old tenant from my high school studies. I…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-11T11:35:35.9266667+00:00
Darius Gherca 20 Reputation points Microsoft Employee
accepted 2025-06-16T20:10:51.8866667+00:00
Darius Gherca 20 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

How a User/Reader role assignment works to allow someone to access my Azure account?

I am the User/Owner of my Azure site. I assigned a User/Reader role to someone. My Azure Access Control (IAM) states that his email address is listed as a role assignment User/Reader. However, he is not able to access my Azure account. What did I do…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-13T18:43:56.9633333+00:00
KatherineKnight-8498 20 Reputation points
commented 2025-06-16T17:39:39.02+00:00
KatherineKnight-8498 20 Reputation points
1 answer

Unable to select Managed Identity when adding role assignment, despite being Owner.

Hello Azure Support Team, I am experiencing a critical permissions issue that is blocking my project. The Goal: I am trying to grant a Managed Identity the 'Storage Blob Data Contributor' role on a Storage Account. This is required for my Azure…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-16T14:16:02.05+00:00
TrubrixAi Azure Admin 0 Reputation points
answered 2025-06-16T17:25:07.6+00:00
Divyesh Govaerdhanan 5,770 Reputation points
1 answer

Issue in connecting cognitive service to communication

I am trying to connect azure cognitive service to communication service. Followed the tutorial in mic learn for the process. I have subscribed a phone number in communication service resource, created a webhook link. Any calls made to the number is…

Azure AI Speech
Azure AI Speech
An Azure service that integrates speech processing into apps and services.
2,045 questions
Azure Communication Services
Azure Communication Services
An Azure communication platform for deploying applications across devices and platforms.
1,219 questions
Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
Azure AI services
Azure AI services
A group of Azure services, SDKs, and APIs designed to make apps more intelligent, engaging, and discoverable.
3,570 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
25,015 questions
asked 2024-06-16T12:29:02.3433333+00:00
Laxmiprasad Putta 0 Reputation points
commented 2025-06-13T19:48:47.95+00:00
TristonH 0 Reputation points
2 answers One of the answers was accepted by the question author.

Manually deleting the 'Unknown' IAM entries at the Subscription levels

What will be the safest method to delete these Unknown entries that are cluttering the IAM roles in all of my Azure Subscriptions, like below? Is there any impact or issue when these entries are deleted manually without any rollback plan?

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-10T12:00:48.9133333+00:00
EnterpriseArchitect 6,021 Reputation points
commented 2025-06-13T11:10:17.69+00:00
Surya Prakash Kotte 2,865 Reputation points Microsoft External Staff Moderator
1 answer

Unable to Save 2 (d) - How to configure role provisioning in AWS Single-Account Access.

I have followed the documents, and am not able to save the 3rd party access keys at step 2 (d) in the heading "How to configure role provisioning in AWS Single-Account Access." Document link:…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-04T14:20:43.8233333+00:00
Surbhi Sharma 0 Reputation points
edited an answer 2025-06-12T21:40:08.3633333+00:00
YukiMi-3210 75 Reputation points Moderator
1 answer One of the answers was accepted by the question author.

AADSTS53003 Conditional Access blocking client credentials token issuance despite no policies applied

Post: I’m using client credentials flow with an Azure AD app registration to call Microsoft Graph API from an internal API. Token acquisition fails with this error: pgsql Copy AADSTS53003: Access has been blocked by Conditional Access policies. The…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-04T12:02:05.64+00:00
Mikail Ceran 20 Reputation points
edited an answer 2025-06-12T21:39:46.6566667+00:00
YukiMi-3210 75 Reputation points Moderator
1 answer One of the answers was accepted by the question author.

Employee downgraded me to owner, stole keys

Help! I am the rightful owner of my server and app, and a rouge contractor just set me as owner, set himself as root and downloaded keys. We cannot access our app, code, databases. How do I get access to be the General Administrator and reset all…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-09T22:55:54.57+00:00
Amanda Besemer Sampson 25 Reputation points
edited an answer 2025-06-12T21:24:07.47+00:00
YukiMi-3210 75 Reputation points Moderator
2 answers

My account was made a member only, and there is no admin on the account anymore.

For some reason, my account was made a member. I am the company/___domain owner, and the only account. I cannot make any changes. Now other apps and sites that I use this account with tell me my account is managed by my org, however I don't have an org to…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-10T01:06:27.97+00:00
dominik Rudnicki 0 Reputation points
commented 2025-06-12T09:04:32.0533333+00:00
SrideviM 5,385 Reputation points Microsoft External Staff Moderator
1 answer

Why group members cannot execute operations on management groups?

Question has been solved: https://learn.microsoft.com/en-us/answers/questions/1316690/why-cant-group-members-operate-the-management-grou *removed content here *

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
25,015 questions
asked 2023-06-23T12:07:46.0966667+00:00
Colin Jochum 20 Reputation points
answered 2025-06-11T12:49:10.18+00:00
Amira Bedhiafi 32,756 Reputation points Volunteer Moderator
1 answer

Owner of a subscription is deleted, how can I set the admin as the new owner?

Owner of a subscription is deleted, how can I set the admin as the new owner?

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-09T16:24:45.43+00:00
Lucien Kazzi 0 Reputation points
commented 2025-06-11T12:33:23.99+00:00
Mallikarjuna Vardham 430 Reputation points Microsoft External Staff Moderator
1 answer

Can't create an azure trial subscription : AADSTS160021

I'm trying to test Azure before subscribing to it. I'm new to the service. I have a personal microsoft account. Then I go to azure website : https://go.microsoft.com/fwlink/?linkid=2227353&clcid=0x40c&l=fr-fr and I click on try azure for free. I…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-04T08:01:56.2366667+00:00
Jose Ca 5 Reputation points
commented 2025-06-11T08:48:57.57+00:00
VigneshwarDuvva-5247 1,990 Reputation points Moderator
2 answers

Azure SSO,use an Alibaba Cloud account to log into Azure

How can this be integrated with Alibaba Cloud's IDaaS service? Please kindly provide guidance. Thank you.Can I use an Alibaba Cloud account to log into Azure? For example, is it possible to invite an Alibaba Cloud account as an external user in Azure?

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-05T05:46:55.59+00:00
凯旋 李 0 Reputation points
edited a comment 2025-06-10T11:55:57.8733333+00:00
Sanoop M 3,730 Reputation points Microsoft External Staff Moderator
1 answer One of the answers was accepted by the question author.

Role Required to assign RBAC PIM assignments

Hello, I am using a service principal for Terraform to deploy PIM assignments for custom roles at the subscription level. These custom roles are Azure Resource/RBAC roles (NOT EntraID roles) reside at the top MG level. I cannot find the correct built-in…

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
949 questions
asked 2025-06-05T12:51:33.97+00:00
Cole Duprey 20 Reputation points
accepted 2025-06-06T12:35:09.6933333+00:00
Cole Duprey 20 Reputation points