Skip to main content

Remediation

From Azure Portal

  1. In the Azure portal, open the portal menu.
  2. Select Microsoft Entra ID.
  3. Under Manage, select Roles and administrators.
  4. Under Administrative Roles, select Global Administrator.

If more than 4 users are assigned

  1. Remove the Global Administrator role from users who do not or no longer require the role.
  2. Assign Global Administrator role via PIM which can be activated when required.
  3. Assign more granular roles to users to conduct their duties.

If only one user is assigned

  1. Provide the Global Administrator role to a trusted user or create a break-glass admin account.