how to audit admin role assignments in entra id
Audits privileged role assignments in Microsoft Entra ID to find excessive or stale admin access. Covers PIM review, eligible vs active assignments, and audit log checks. Use for quarterly privileged-access reviews. Not for general user access reviews.
TL;DR
In Entra go to Identity Governance > Privileged Identity Management and review every eligible and active assignment for Global Administrator and other privileged roles. Remove standing active assignments, convert to eligible-with-approval, and check the audit log for who granted what.
The error
(Compliance review; no error. "Who has admin and why?")Steps
- Entra admin center > Identity Governance > PIM > Microsoft Entra roles > Assignments. Expected: full list of eligible and active assignments. Export it.
- Flag every ACTIVE (standing) assignment to privileged roles, especially Global Administrator. Expected: list of standing admins. Standing access should be near zero; convert to eligible.
- For each assignment, check the justification and the owner who approved it. Expected: documented business reason. "Historical" is not a reason.
- Check Audit logs for role assignment changes in the last 90 days. Expected: each change maps to a ticket or approval. Unmapped grants are findings.
- Remove or convert unjustified assignments, then set up access reviews in PIM to repeat this quarterly. Expected: recurring review scheduled.
When to use
- Quarterly privileged access review
- Pre-audit (SOC 2, ISO 27001) preparation
- After admin staff changes
When not to use
- Reviewing regular user app access (use access certifications)
- Investigating a specific compromise (incident response flow)
Compatibility
- Microsoft Entra ID P2 (PIM requires P2)
Variants
No PIM license
Review via Roles and administrators > assignments manually; same questions, more spreadsheet.
Too many Global Admins
Common finding. Most can drop to narrower roles (User Administrator, Helpdesk Administrator).
Why it happens
Admin rights accumulate through role changes, projects, and "temporary" grants that never expire. Without scheduled review, the privileged population only grows.
Edge cases
- Break-glass accounts: keep them, document them, exclude from reviews, and monitor their use.
- Service principals with privileged roles: include them; they are often forgotten.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_G4wrPvC9w2cNMHHG2WTR1A