I missed the deadline of transition to RBAC in Azure by 31 August 2024, access to all resources is lost.

Gaz Zhao 20 Reputation points
2024-09-08T12:48:51.02+00:00

I lost access to our resources because I missed the deadline to transition to RBAC in Azure by August 31, 2024. Currently, there are three "member" user types in Entra ID, and I am one of them. I used to be the admin in the old classic Azure administrator roles. Is there any way for me to regain my admin identity in Entra ID and access our old resources?

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
814 questions
0 comments No comments
{count} votes

Accepted answer
  1. Sandeep G-MSFT 19,436 Reputation points Microsoft Employee
    2024-09-09T03:54:45.4433333+00:00

    @Gaz Zhao

    Thank you for posting this in Microsoft Q&A.

    As I understand you have missed the deadline to migrate classic administrators to RBAC. Due to this you do not have access on the subscription now.

    You can follow below steps to get access on to the subscription as Owner.

    I see that you have only 3 users in your Entra ID. to fix this issue you will need atleast one user who has Global admin role assigned in Entra ID.

    Follow these steps to elevate access for a Global Administrator using the Azure portal.

    Sign in to the Azure portal as a Global Administrator.

    If you are using Microsoft Entra Privileged Identity Management, activate your Global Administrator role assignment.

    Open Microsoft Entra ID.

    1. Under Manage, select Properties. Select Properties for Microsoft Entra properties - screenshot
    2. Under Access management for Azure resources, set the toggle to Yes. Access management for Azure resources - screenshot When you set the toggle to Yes, you are assigned the User Access Administrator role in Azure RBAC at root scope (/). This grants you permission to assign roles in all Azure subscriptions and management groups associated with this Microsoft Entra directory. This toggle is only available to users who are assigned the Global Administrator role in Microsoft Entra ID. When you set the toggle to No, the User Access Administrator role in Azure RBAC is removed from your user account. You can no longer assign roles in all Azure subscriptions and management groups that are associated with this Microsoft Entra directory. You can view and manage only the Azure subscriptions and management groups to which you have been granted access.
    3. Click Save to save your setting. This setting is not a global property and applies only to the currently signed in user. You can't elevate access for all members of the Global Administrator role.
    4. Sign out and sign back in to refresh your access. You should now have access to all subscriptions and management groups in your directory. When you view the Access control (IAM) pane, you'll notice that you have been assigned the User Access Administrator role at root scope. Subscription role assignments with root scope - screenshot
    5. Make the changes you need to make at elevated access. For information about assigning roles, see Assign Azure roles using the Azure portal. If you are using Privileged Identity Management, see Discover Azure resources to manage or Assign Azure resource roles. Perform the steps in the following section to remove your elevated access.

    NOTE: Once you sign out and sign back in to refresh your access, you can assign an owner role to you account under subscription.

    Once you have the owner role assigned on the subscription, we would recommend you remove elevated access for your account.

    You can follow steps in below article to remove elevated access for your account.

    Let us know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.