Microsoft adds user actions to the Security Administrator role
Read OriginalMicrosoft has added four identity containment actions to the Entra ID Security Administrator role, allowing it to disable/re-enable users, revoke sessions, and reset passwords. This expansion from 82 to 86 directory actions gives the role direct incident-response capabilities. The tracker also noted 25 inferred Microsoft Graph permissions, including User.EnableDisableAccount.All and User.RevokeSessions.All. This overlaps with the Entra SOC Identity Responder role, which is more scoped. Administrators should review assignments to avoid over-privileged access. The permissions temporarily dropped but are expected to return.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser