## TL;DR
In Entra go to Identity Governance > Privileged Identity Management and review every eligible and active assignment for Global Administrator and other privileged roles. Remove standing active assignments, convert to eligible-with-approval, and check the audit log for who granted what.

## The error
```text
(Compliance review; no error. "Who has admin and why?")
```

## Steps
1. Entra admin center > Identity Governance > PIM > Microsoft Entra roles > Assignments. Expected: full list of eligible and active assignments. Export it.
2. Flag every ACTIVE (standing) assignment to privileged roles, especially Global Administrator. Expected: list of standing admins. Standing access should be near zero; convert to eligible.
3. For each assignment, check the justification and the owner who approved it. Expected: documented business reason. "Historical" is not a reason.
4. Check Audit logs for role assignment changes in the last 90 days. Expected: each change maps to a ticket or approval. Unmapped grants are findings.
5. Remove or convert unjustified assignments, then set up access reviews in PIM to repeat this quarterly. Expected: recurring review scheduled.

## When to use
- Quarterly privileged access review
- Pre-audit (SOC 2, ISO 27001) preparation
- After admin staff changes

## When not to use
- Reviewing regular user app access (use access certifications)
- Investigating a specific compromise (incident response flow)

## Compatibility
- Microsoft Entra ID P2 (PIM requires P2)

## Variants
### No PIM license
Review via Roles and administrators > assignments manually; same questions, more spreadsheet.
### Too many Global Admins
Common finding. Most can drop to narrower roles (User Administrator, Helpdesk Administrator).

## Why it happens
Admin rights accumulate through role changes, projects, and "temporary" grants that never expire. Without scheduled review, the privileged population only grows.

## Edge cases
- Break-glass accounts: keep them, document them, exclude from reviews, and monitor their use.
- Service principals with privileged roles: include them; they are often forgotten.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_G4wrPvC9w2cNMHHG2WTR1A
