简体   繁体   中英

Azure User Admin right to delete guest users

I have User Admin role assigned and just noticed that am not able to delete external users. the user admin has right: microsoft.directory/users/delete and i guess that is not enough. the global admin has right: microsoft.directory/users/allProperties/allTasks

Create and delete users, and read and update all properties.

Do you know if there is any other role that grants the right to delete external users? or am i missing here something?

I have User Admin role assigned and just noticed that am not able to delete external users.

在此处输入图像描述

You can check user admin roles here. As per document as shown in below image for this User admin role Delete or Restore users is not applicable.在此处输入图像描述

As per your requirement Global Administrator has this delete user access privilege. Here you can go through Global Administrator rights.
在此处输入图像描述

there is any other role that grants the right to delete external users?
  • AFAIK the Global Administrator role is the only built-in role in Azure AD that grants the ability ** to delete external users but If you do not want to assign the Global Administrator role but still you want to be able to delete external users, you can create a custom role and assign the "microsoft.directory/users/delete" permission to it.

  • In Azure You can create custom role in different ways like ~Using Azure portal. ~Using PowerShell ~Using CLI

  • To create custom role using portal check your custom role is enabled or disabled as shown in below image Select your subscription or Resource group >> Access control >> +Add >> Add Custom role.

在此处输入图像描述

The technical post webpages of this site follow the CC BY-SA 4.0 protocol. If you need to reprint, please indicate the site URL or the original address.Any question please contact:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM