Start here
The high findings, grouped so one action fixes many.
- Alex Rivera · Owner on ProductionAzure RBACRemove the permanent Owner assignment on Production and make Alex Rivera eligible for it in PIM. Open in portal
- Deploy Bot · Owner on ProductionAzure RBACRemove the permanent Owner assignment on Production or make Deploy Bot eligible for it in PIM; PIM eligibility does not apply to workload identities. Open in portal
- Taylor Kim · Security Administrator on DirectoryUnused eligibilityTaylor Kim's account is disabled, and still holds this eligibility. Remove the eligibility, or move it behind an access review. Open in portal
- Tier 0 Admins · Global Administrator on Directory · 2 people through 2 nested groupsEntra rolesMake Tier 0 Admins's Global Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal
- Helpdesk Leads · Privileged Role Administrator on Directory · 1 personEntra rolesMake Helpdesk Leads's Privileged Role Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal
- Legacy Ops · Security Administrator on Directory · 1 personEntra rolesMake Legacy Ops's Security Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal
- Alex Rivera · Global Administrator on DirectoryEntra rolesRemove the permanent Global Administrator assignment and make Alex Rivera eligible for it in PIM. Open in portal
- Priya Natarajan guest · Security Administrator on DirectoryEntra rolesRemove the permanent Security Administrator assignment and make Priya Natarajan eligible for it in PIM. Open in portal
- Tier 0 Admins · Tier 0 Admins (owner) on Tier 0 Admins · 1 personPIM for GroupsTier 0 Admins is managed by PIM for Groups, but Sam Chen is a permanent owner. Convert the assignment to eligible. Open in portal
- Priya Natarajan guest · Security Administrator on DirectoryGuestsGuest Priya Natarajan holds Security Administrator permanently. Guests should hold privileged roles only as eligible, if at all. Open in portal
Entra roles
9 high2 medium
Permanent active directory role assignments, held directly or through groups.
ENTRA-GROUP-PERMANENT
highA group holds a permanent active Entra role3 groups · 4 people
Make Tier 0 Admins's Global Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal
- Global AdministratorDirectory
- Tier 0 Admins1 person direct · 1 nested group
- Sam Chen
- Platform Team0 people direct · 1 nested group
- Platform On-call1 person direct
- Casey Wong
- Platform On-call1 person direct
- Tier 0 Admins1 person direct · 1 nested group
People reached (2)
| Person | Through | Remedy |
|---|---|---|
| Casey Wong casey.wong@contoso.com | Tier 0 Admins ← Platform Team ← Platform On-call | Casey Wong holds Global Administrator permanently through Tier 0 Admins ← Platform Team ← Platform On-call. Make the membership or the group's assignment eligible. Open in portal |
| Sam Chen sam.chen@contoso.com | Tier 0 Admins | Sam Chen holds Global Administrator permanently through Tier 0 Admins. Make the membership or the group's assignment eligible. Open in portal |
Make Helpdesk Leads's Privileged Role Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal
- Privileged Role AdministratorDirectory
- Helpdesk Leads1 person direct
- Morgan Diaz
- Helpdesk Leads1 person direct
People reached (1)
| Person | Through | Remedy |
|---|---|---|
| Morgan Diaz morgan.diaz@contoso.com | Helpdesk Leads | Morgan Diaz holds Privileged Role Administrator permanently through Helpdesk Leads. Make the membership or the group's assignment eligible. Open in portal |
Make Legacy Ops's Security Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal
- Security AdministratorDirectory
- Legacy Ops1 person direct
- Riley Park
- Legacy Ops1 person direct
People reached (1)
| Person | Through | Remedy |
|---|---|---|
| Riley Park riley.park@contoso.com | Legacy Ops | Riley Park holds Security Administrator permanently through Legacy Ops. Make the membership or the group's assignment eligible. Open in portal |
ENTRA-USER-PERMANENT
highA user holds a permanent active Entra role directly2 findings
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Alex Rivera alex.rivera@contoso.com | Global Administrator Entra | Directory directory | direct | Remove the permanent Global Administrator assignment and make Alex Rivera eligible for it in PIM. Open in portal |
| Priya Natarajan priya.natarajan_fabrikam.com#EXT#@contoso.com guest | Security Administrator Entra | Directory directory | direct | Remove the permanent Security Administrator assignment and make Priya Natarajan eligible for it in PIM. Open in portal |
ENTRA-GROUP-NOT-ASSIGNABLE
mediumA role is assigned to a group that is not role-assignable1 finding
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Legacy Ops group | Security Administrator Entra | Directory directory | direct | Legacy Ops is not role-assignable, so PIM for Groups cannot govern it. Recreate it as a role-assignable group and move the assignment. Open in portal |
ENTRA-GROUP-NOT-PIM
mediumA role-assignable group carrying a role is not onboarded to PIM for Groups1 finding
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Helpdesk Leads group | Privileged Role Administrator Entra | Directory directory | direct | Onboard Helpdesk Leads to PIM for Groups so its membership can be eligible instead of permanent. Open in portal |
PIM for Groups
1 high
Groups PIM already manages that still have permanent members or owners.
GROUP-MEMBER-PERMANENT
highA group managed by PIM for Groups still has a permanent member or owner1 group · 1 person
Tier 0 Admins is managed by PIM for Groups, but Sam Chen is a permanent owner. Convert the assignment to eligible. Open in portal
- Tier 0 Admins (owner)Tier 0 Admins
- Tier 0 Admins1 person direct
- Sam Chen
- Tier 0 Admins1 person direct
People reached (1)
| Person | Through | Remedy |
|---|---|---|
| Sam Chen sam.chen@contoso.com | direct | Tier 0 Admins is managed by PIM for Groups, but Sam Chen is a permanent owner. Convert the assignment to eligible. Open in portal |
Azure RBAC
2 high2 mediumunder-counts
Permanent privileged Azure role assignments at any scope.
AZURE-PERMANENT
highA permanent privileged Azure role assignment2 findings
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Alex Rivera alex.rivera@contoso.com | Owner Azure | Production subscription | direct | Remove the permanent Owner assignment on Production and make Alex Rivera eligible for it in PIM. Open in portal |
| Deploy Bot | Owner Azure | Production subscription | direct | Remove the permanent Owner assignment on Production or make Deploy Bot eligible for it in PIM; PIM eligibility does not apply to workload identities. Open in portal |
AZURE-PERMANENT
mediumA permanent privileged Azure role assignment1 group · 1 person
Make the group's Contributor assignment on rg-payments eligible in PIM for Azure resources, or govern the group's membership with PIM for Groups. Open in portal
- Contributorrg-payments
- Cloud Ops1 person direct
- Jordan Lee
- Cloud Ops1 person direct
People reached (1)
| Person | Through | Remedy |
|---|---|---|
| Jordan Lee jordan.lee@contoso.com | Cloud Ops | Jordan Lee holds Contributor on rg-payments permanently through Cloud Ops. Open in portal |
Guests
1 high
Guests holding a permanent privileged role, directly or through a group.
GUEST-PERMANENT
highA guest holds a permanent privileged role1 finding
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Priya Natarajan priya.natarajan_fabrikam.com#EXT#@contoso.com guest | Security Administrator Entra | Directory directory | direct | Guest Priya Natarajan holds Security Administrator permanently. Guests should hold privileged roles only as eligible, if at all. Open in portal |
Workload identities
2 info
Service principals and managed identities holding permanent privileged roles; PIM eligibility does not apply.
SP-PERMANENT
infoA service principal or managed identity holds a permanent privileged role2 findings
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Deploy Bot | Global Administrator Entra | Directory directory | direct | Deploy Bot holds Global Administrator permanently. PIM eligibility does not apply to workload identities; review whether the workload identity needs the role at all, scope it down, or replace it with a narrower custom role. Open in portal |
| Deploy Bot | Owner Azure | Production subscription | direct | Deploy Bot holds Owner permanently. PIM eligibility does not apply to workload identities; review whether the workload identity needs the role at all, scope it down, or replace it with a narrower custom role. Open in portal |
Unused eligibility
1 high4 medium
Eligibilities nobody exercises: never activated, dormant, or held by a principal that cannot use them.
ELIGIBLE-ORPHANED
high1 finding
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Taylor Kim taylor.kim@contoso.com | Security Administrator Entra | Directory directory | direct | Taylor Kim's account is disabled, and still holds this eligibility. Remove the eligibility, or move it behind an access review. Open in portal |
ELIGIBLE-DORMANT
medium1 finding
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Morgan Diaz morgan.diaz@contoso.com | Global Administrator Entra | Directory directory | direct | Last activated 2026-03-20, 177 days ago; granted 620 days ago. Remove the eligibility, or move it behind an access review. Open in portal |
ELIGIBLE-NEVER-ACTIVATED
medium3 findings
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Casey Wong casey.wong@contoso.com | Global Administrator Entra | Directory directory | direct | Granted 2025-01-01 (620 days ago) and never activated in the 180 days examined (since 2026-03-17). Remove the eligibility, or move it behind an access review. Open in portal |
| Jordan Lee jordan.lee@contoso.com | Owner Azure | Production subscription | direct | Granted 2025-01-01 (620 days ago) and never activated in the 180 days examined (since 2026-03-17). Remove the eligibility, or move it behind an access review. Open in portal |
| Riley Park riley.park@contoso.com | Global Administrator Entra | Directory directory | direct | Granted 2025-01-01 (620 days ago) and never activated in the 180 days examined (since 2026-03-17). Remove the eligibility, or move it behind an access review. Open in portal |
Hygiene
1 medium5 low
Eligibilities without an end date and the Global Administrator count.
GA-COUNT
mediumFewer than 2 or more than 5 people can become Global Administrator1 finding
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Contoso | Global Administrator Entra | Directory directory | direct | 7 principals can become Global Administrator (permanent or eligible). Microsoft recommends at most five; move the rest to narrower roles. Open in portal |
ELIGIBLE-NO-END
lowAn eligibility has no end date5 findings
| Principal | Role | Scope | How | Remedy |
|---|---|---|---|---|
| Alex Rivera alex.rivera@contoso.com | Tier 0 Admins (member) Group | Tier 0 Admins group | direct | Give the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal |
| Jordan Lee jordan.lee@contoso.com | Global Administrator Entra | Directory directory | direct | Give the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal |
| Jordan Lee jordan.lee@contoso.com | Owner Azure | Production subscription | direct | Give the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal |
| Morgan Diaz morgan.diaz@contoso.com | Global Administrator Entra | Directory directory | direct | Give the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal |
| Riley Park riley.park@contoso.com | Global Administrator Entra | Directory directory | direct | Give the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal |
Coverage
1 skipped
Which sources were read and which were skipped.
| Source | State | What it means |
|---|---|---|
| Entra role assignments | read | Every active assignment and eligibility. |
| Groups | read | Members of role-assigned groups, nested groups included. |
| PIM for Groups | read | Active and eligible memberships of PIM-managed groups. |
| Azure subscriptions | read | Role assignments in the subscriptions the account can read. |
| Azure management groups | skipped | Azure management groups are not readable by this account; scanned subscriptions only. |
| Principals | read | Names, sign-in names and guest status. |
| Activation history | read | PIM activations in the lookback window, from the directory audit log and ARM's request history. |
Appendix
Options, scopes requested, evidence ids
Options: all roles off; minimum severity info; ignored rules: none.
PIM activation history examined: 2026-03-17 to 2026-09-13 (180 days, Entra, Group, Azure). Directory audit logs are retained for 30 days by default, so the tenant may hold less than this window.
Read-only Microsoft Graph scopes requested: User.Read, RoleManagement.Read.Directory, PrivilegedAssignmentSchedule.Read.AzureADGroup, PrivilegedEligibilitySchedule.Read.AzureADGroup, GroupMember.Read.All, User.ReadBasic.All, AuditLog.Read.All. Nothing was written to the tenant.
This report contains personal data (names and sign-in names of people who hold roles). Handle it as you would any access review.
Evidence ids
| Rule | Principal id | Assignment id | Start | End | Type |
|---|---|---|---|---|---|
| AZURE-PERMANENT | u-alex | ra-alex-owner | — | — | Classic |
| AZURE-PERMANENT | sp-deploy | ra-deploy-owner | — | — | Classic |
| ELIGIBLE-ORPHANED | u-taylor | e-taylor-sec | 2025-01-01 | 2027-01-01 | Direct |
| ENTRA-GROUP-PERMANENT | u-casey | a-tier0-ga | 2025-01-01 | — | Assigned |
| ENTRA-GROUP-PERMANENT | g-helpdesk | a-helpdesk-pra | 2025-01-01 | — | Assigned |
| ENTRA-GROUP-PERMANENT | g-legacy | a-legacy-sec | 2025-01-01 | — | Assigned |
| ENTRA-GROUP-PERMANENT | u-morgan | a-helpdesk-pra | 2025-01-01 | — | Assigned |
| ENTRA-GROUP-PERMANENT | u-riley | a-legacy-sec | 2025-01-01 | — | Assigned |
| ENTRA-GROUP-PERMANENT | u-sam | a-tier0-ga | 2025-01-01 | — | Assigned |
| ENTRA-GROUP-PERMANENT | g-tier0 | a-tier0-ga | 2025-01-01 | — | Assigned |
| ENTRA-USER-PERMANENT | u-alex | a-alex-ga | 2025-01-01 | — | Assigned |
| ENTRA-USER-PERMANENT | u-priya | a-priya-sec | 2025-01-01 | — | Assigned |
| GROUP-MEMBER-PERMANENT | u-sam | gp-sam-owner | 2025-01-01 | — | Assigned |
| GUEST-PERMANENT | u-priya | a-priya-sec | 2025-01-01 | — | Assigned |
| AZURE-PERMANENT | g-cloudops | ra-cloudops-contrib | — | — | Classic |
| AZURE-PERMANENT | u-jordan | ra-cloudops-contrib | — | — | Classic |
| ELIGIBLE-DORMANT | u-morgan | e-morgan-ga | 2025-01-01 | — | Direct |
| ELIGIBLE-NEVER-ACTIVATED | u-casey | e-casey-ga | 2025-01-01 | 2027-03-01 | Direct |
| ELIGIBLE-NEVER-ACTIVATED | u-jordan | ae-jordan-owner | 2025-01-01 | — | Schedule |
| ELIGIBLE-NEVER-ACTIVATED | u-riley | e-riley-ga | 2025-01-01 | — | Direct |
| ENTRA-GROUP-NOT-ASSIGNABLE | g-legacy | a-legacy-sec | 2025-01-01 | — | Assigned |
| ENTRA-GROUP-NOT-PIM | g-helpdesk | a-helpdesk-pra | 2025-01-01 | — | Assigned |
| GA-COUNT | 5d3a9c1e-4f7b-4a2d-9e8c-0b6f1a2d3c4e | global-administrator-count | — | — | — |
| ELIGIBLE-NO-END | u-alex | gp-alex-member | 2025-01-01 | — | — |
| ELIGIBLE-NO-END | u-jordan | e-jordan-ga | 2025-01-01 | — | Direct |
| ELIGIBLE-NO-END | u-jordan | ae-jordan-owner | 2025-01-01 | — | Schedule |
| ELIGIBLE-NO-END | u-morgan | e-morgan-ga | 2025-01-01 | — | Direct |
| ELIGIBLE-NO-END | u-riley | e-riley-ga | 2025-01-01 | — | Direct |
| SP-PERMANENT | sp-deploy | a-deploy-ga | 2025-01-01 | — | Assigned |
| SP-PERMANENT | sp-deploy | ra-deploy-owner | — | — | Classic |