Who Gave This Account an Admin Role in Entra ID?

An account has turned up with an admin role in Microsoft Entra ID and nobody remembers granting it. Here is how to see who assigned it, when and from which IP address, and which Global Administrators are permanent.

Cover: Who gave this account an admin role? with the Active Identity Guardian audit detail of a User Administrator role assigned by jordan.reid@contoso.com

Follow along live. Open this exact view in the read-only demo while you read. No sign-up needed.

Try It Live
On this page
  1. Why the built-in tools make this hard
  2. Find who assigned the role
  3. Find standing Global Administrator access
  4. Get alerted
  5. What to do next
  6. Summary

During a routine check you notice that clara.moreau@contoso.com now holds the User Administrator role in Microsoft Entra ID, and nobody on the team remembers granting it. Who assigned the role? When, and from where? And while you are looking, which accounts hold Global Administrator all the time?

Admins ask this on Microsoft Q&A in many forms, from finding out who made a user a Global Administrator to tracking which users were moved into and out of admin roles. Admin roles decide who can change users, apps and security settings across the tenant, so an assignment nobody can explain needs an answer quickly.

Why the built-in tools make this hard

Entra ID does log role assignments, but answering the question later is harder than it should be:

  • The record doesn't last. The Entra audit log keeps 7 days of history on the free tier and 30 days with P1 or P2, and upgrading your licence doesn't bring back older entries. A role granted two months ago may have left nothing you can still find there.
  • One kind of change, several names. A direct assignment, an assignment through Privileged Identity Management and membership of a role-assignable group are logged as different activities, so a search for one misses the others.
  • Nobody is told. Outside Privileged Identity Management, Entra ID doesn't email anyone when an account gets an admin role, and PIM's notifications and alerts need a Microsoft Entra ID P2 or ID Governance licence. Otherwise you have to build the alert yourself.
  • Standing access is the default. Microsoft recommends fewer than five Global Administrators, and just-in-time access to admin roles through Privileged Identity Management, which also needs P2. Without it, every assignment is permanent, and finding them all is a manual review.
  • On-premises admins are somewhere else. Admin rights in Active Directory are recorded in your domain controllers' logs, not in Entra ID, so an account that is an admin in both shows up in two separate places.

Active Identity Guardian collects the Entra ID audit log into its own audit trail, keeps it for as long as you choose, and checks your admin roles against a set of privileged-role rules. Here is how it looks in the demo.

Find who assigned the role

1Search the audit trail for role assignments

In Audit Events, search for Add member to role. Every Entra ID role assignment in the last 7 days is listed, newest first, with the account that received the role, who assigned it and the IP address they used. The demo has 37 this week, and the panels above the list show who has been assigning roles most often.

Audit Events searched for Add member to role over the last 7 days: 37 Entra ID role assignments, each with the account, who assigned the role and the source IP address, the newest flagged New IP for actor
1 Search for role assignments. 2 The newest: jordan.reid@contoso.com assigned a role to clara.moreau@contoso.com at 15:14 today, from an IP address not seen for that admin before.

2Open the assignment

Click the row. The summary shows who made the change, the account that received the role and the IP address the change came from, followed by the role itself: User Administrator. The change is also flagged New IP for actor.

The role assignment detail: changed by jordan.reid@contoso.com from 203.0.113.86 on clara.moreau@contoso.com, Role.DisplayName empty before and User Administrator after, flagged New IP for actor
1 Who made the change, the account that received the role and the source IP address. 2 The role that was assigned: User Administrator.

From here, show all by user lists everything else jordan.reid@contoso.com has changed, and History shows every recorded change to clara.moreau's account, so you can see what happened before and after the role arrived.

Find standing Global Administrator access

3Check who is a Global Administrator all the time

A role assigned today is one question. Who holds the most powerful role permanently is another. In Exposures, the Permanent Global Administrator Assignments rule lists accounts with a permanent, rather than just-in-time, Global Administrator assignment. The demo has two: the Contoso Administrator account, which Alex Morgan is working on, and a Security Administrator account, for which Priya Shah has recorded an accepted risk.

The Permanent Global Administrator Assignments rule expanded: two accounts with a permanent Global Administrator assignment, one in progress with Alex Morgan and one accepted as a risk by Priya Shah
1 What the rule checks: Global Administrator assignments that are permanent instead of just-in-time. 2 The accounts affected, each with a status and an owner.

4Review every check on admin roles

Filter Exposures by the Entra ID — Privileged Roles category to see every check on admin roles together: privileged roles without MFA, admins who are also privileged in on-premises Active Directory, guests with privileged roles, too many Global Administrators and more. Checks with nothing to report are marked No findings, so you can see what was checked as well as what was found.

Exposures filtered to Entra ID — Privileged Roles: permanent Global Administrators, MFA not enforced for privileged roles, admins also privileged in on-premises AD, a privileged role without MFA Conditional Access, and checks with no findings
1 The Entra ID — Privileged Roles category. 2 Every check on admin roles, with how many findings each one has.

Get alerted

5Send new findings to email or Teams

Under Settings > Notifications, set the finding scope to All findings so that new exposures, such as a new permanent Global Administrator or a guest given a privileged role, are sent to email (SMTP or Office 365) or Microsoft Teams.

Settings, Notifications: alerts to email over SMTP or Office 365 and to Microsoft Teams, with a finding scope and a choice of when to notify
1 What is sent and when: choose All findings to include exposures such as permanent Global Administrators. 2 Where it goes: email or Microsoft Teams. (The demo is read-only, so these settings can't be changed there.)

What to do next

  • Confirm the assignment. Ask the admin who made it and check it against a request. You know who, when and from where, so it is a short conversation.
  • Remove what nobody can explain. Take the role away and review what the account did while it had it.
  • Use the narrowest role that does the job. Most admin tasks need a far more limited role than Global Administrator.
  • Keep Global Administrators few. Microsoft recommends assigning the role to fewer than five people, plus emergency access accounts so that you can't be locked out of the tenant.

Summary

  • The Entra audit log records role assignments under several activity names and keeps them for 7 or 30 days, and without Privileged Identity Management nobody is emailed about a new admin role.
  • Active Identity Guardian keeps every role assignment in its audit trail, with who made it, when and from which IP address, and flags unusual sources.
  • Privileged-role rules flag permanent Global Administrators and other risky admin access, each with an owner and a status, and new findings can be sent to email or Microsoft Teams.

Try it yourself

Everything above comes from the Active Identity Guardian demo, which runs on synthetic data and is read-only. Open the same view and click through it, with no sign-up.

Try It LiveTalk to Us

Written by

Peter Chan

Kinleong Consulting

Peter Chan has more than 15 years of experience in identity security and Microsoft technologies.