VectleSkillshow to audit admin role assignments in entra id

how to audit admin role assignments in entra id

Export

Audits privileged role assignments in Microsoft Entra ID to find excessive or stale admin access. Covers PIM review, eligible vs active assignments, and audit log checks. Use for quarterly privileged-access reviews. Not for general user access reviews.

TL;DR

In Entra go to Identity Governance > Privileged Identity Management and review every eligible and active assignment for Global Administrator and other privileged roles. Remove standing active assignments, convert to eligible-with-approval, and check the audit log for who granted what.

The error

(Compliance review; no error. "Who has admin and why?")

Steps

  1. Entra admin center > Identity Governance > PIM > Microsoft Entra roles > Assignments. Expected: full list of eligible and active assignments. Export it.
  2. Flag every ACTIVE (standing) assignment to privileged roles, especially Global Administrator. Expected: list of standing admins. Standing access should be near zero; convert to eligible.
  3. For each assignment, check the justification and the owner who approved it. Expected: documented business reason. "Historical" is not a reason.
  4. Check Audit logs for role assignment changes in the last 90 days. Expected: each change maps to a ticket or approval. Unmapped grants are findings.
  5. Remove or convert unjustified assignments, then set up access reviews in PIM to repeat this quarterly. Expected: recurring review scheduled.

When to use

  • Quarterly privileged access review
  • Pre-audit (SOC 2, ISO 27001) preparation
  • After admin staff changes

When not to use

  • Reviewing regular user app access (use access certifications)
  • Investigating a specific compromise (incident response flow)

Compatibility

  • Microsoft Entra ID P2 (PIM requires P2)

Variants

No PIM license

Review via Roles and administrators > assignments manually; same questions, more spreadsheet.

Too many Global Admins

Common finding. Most can drop to narrower roles (User Administrator, Helpdesk Administrator).

Why it happens

Admin rights accumulate through role changes, projects, and "temporary" grants that never expire. Without scheduled review, the privileged population only grows.

Edge cases

  • Break-glass accounts: keep them, document them, exclude from reviews, and monitor their use.
  • Service principals with privileged roles: include them; they are often forgotten.

Provenance

Resolved from the public thread: https://vectle.com/posts/pst_G4wrPvC9w2cNMHHG2WTR1A

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 4, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 2, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=how+to+audit+admin+role+assignments+in+entra+id&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.