elevate-audit · standing privileged access

Contoso

7 people and 1 workload identity hold standing privileged access in Contoso. Azure management groups were not scanned, so the Azure section under-counts.

Start here

The high findings, grouped so one action fixes many.

  1. Alex Rivera · Owner on ProductionAzure RBACRemove the permanent Owner assignment on Production and make Alex Rivera eligible for it in PIM. Open in portal
  2. Deploy Bot · Owner on ProductionAzure RBACRemove the permanent Owner assignment on Production or make Deploy Bot eligible for it in PIM; PIM eligibility does not apply to workload identities. Open in portal
  3. Taylor Kim · Security Administrator on DirectoryUnused eligibilityTaylor Kim's account is disabled, and still holds this eligibility. Remove the eligibility, or move it behind an access review. Open in portal
  4. Tier 0 Admins · Global Administrator on Directory · 2 people through 2 nested groupsEntra rolesMake Tier 0 Admins's Global Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal
  5. Helpdesk Leads · Privileged Role Administrator on Directory · 1 personEntra rolesMake Helpdesk Leads's Privileged Role Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal
  6. Legacy Ops · Security Administrator on Directory · 1 personEntra rolesMake Legacy Ops's Security Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal
  7. Alex Rivera · Global Administrator on DirectoryEntra rolesRemove the permanent Global Administrator assignment and make Alex Rivera eligible for it in PIM. Open in portal
  8. Priya Natarajan guest · Security Administrator on DirectoryEntra rolesRemove the permanent Security Administrator assignment and make Priya Natarajan eligible for it in PIM. Open in portal
  9. Tier 0 Admins · Tier 0 Admins (owner) on Tier 0 Admins · 1 personPIM for GroupsTier 0 Admins is managed by PIM for Groups, but Sam Chen is a permanent owner. Convert the assignment to eligible. Open in portal
  10. Priya Natarajan guest · Security Administrator on DirectoryGuestsGuest Priya Natarajan holds Security Administrator permanently. Guests should hold privileged roles only as eligible, if at all. Open in portal

Entra roles

9 high2 medium

Permanent active directory role assignments, held directly or through groups.

ENTRA-GROUP-PERMANENT

highA group holds a permanent active Entra role3 groups · 4 people
Tier 0 AdminsgroupgrantsGlobal Administratoron Directory to 2 people through 2 nested groups

Make Tier 0 Admins's Global Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal

Membership
  • Global AdministratorDirectory
    • Tier 0 Admins1 person direct · 1 nested group
      • Sam Chen
      • Platform Team0 people direct · 1 nested group
        • Platform On-call1 person direct
          • Casey Wong
How the groups nestGlobal AdministratorGlobal Administra…Entra rolePlatform On-callPlatform On-call1 personPlatform TeamPlatform Team0 peopleTier 0 AdminsTier 0 Admins1 person
People reached (2)
PersonThroughRemedy
Casey Wong
casey.wong@contoso.com
Tier 0 Admins ← Platform Team ← Platform On-callCasey Wong holds Global Administrator permanently through Tier 0 Admins ← Platform Team ← Platform On-call. Make the membership or the group's assignment eligible. Open in portal
Sam Chen
sam.chen@contoso.com
Tier 0 AdminsSam Chen holds Global Administrator permanently through Tier 0 Admins. Make the membership or the group's assignment eligible. Open in portal
Helpdesk LeadsgroupgrantsPrivileged Role Administratoron Directory to 1 person directly

Make Helpdesk Leads's Privileged Role Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal

Membership
  • Privileged Role AdministratorDirectory
    • Helpdesk Leads1 person direct
      • Morgan Diaz
People reached (1)
PersonThroughRemedy
Morgan Diaz
morgan.diaz@contoso.com
Helpdesk LeadsMorgan Diaz holds Privileged Role Administrator permanently through Helpdesk Leads. Make the membership or the group's assignment eligible. Open in portal
Legacy OpsgroupgrantsSecurity Administratoron Directory to 1 person directly

Make Legacy Ops's Security Administrator assignment eligible, or keep it active and make the group's members eligible through PIM for Groups. Open in portal

Membership
  • Security AdministratorDirectory
    • Legacy Ops1 person direct
      • Riley Park
People reached (1)
PersonThroughRemedy
Riley Park
riley.park@contoso.com
Legacy OpsRiley Park holds Security Administrator permanently through Legacy Ops. Make the membership or the group's assignment eligible. Open in portal

ENTRA-USER-PERMANENT

highA user holds a permanent active Entra role directly2 findings
PrincipalRoleScopeHowRemedy
Alex Rivera
alex.rivera@contoso.com
Global Administrator
Entra
Directory
directory
directRemove the permanent Global Administrator assignment and make Alex Rivera eligible for it in PIM. Open in portal
Priya Natarajan
priya.natarajan_fabrikam.com#EXT#@contoso.com guest
Security Administrator
Entra
Directory
directory
directRemove the permanent Security Administrator assignment and make Priya Natarajan eligible for it in PIM. Open in portal

ENTRA-GROUP-NOT-ASSIGNABLE

mediumA role is assigned to a group that is not role-assignable1 finding
PrincipalRoleScopeHowRemedy
Legacy Ops groupSecurity Administrator
Entra
Directory
directory
directLegacy Ops is not role-assignable, so PIM for Groups cannot govern it. Recreate it as a role-assignable group and move the assignment. Open in portal

ENTRA-GROUP-NOT-PIM

mediumA role-assignable group carrying a role is not onboarded to PIM for Groups1 finding
PrincipalRoleScopeHowRemedy
Helpdesk Leads groupPrivileged Role Administrator
Entra
Directory
directory
directOnboard Helpdesk Leads to PIM for Groups so its membership can be eligible instead of permanent. Open in portal

PIM for Groups

1 high

Groups PIM already manages that still have permanent members or owners.

GROUP-MEMBER-PERMANENT

highA group managed by PIM for Groups still has a permanent member or owner1 group · 1 person
Tier 0 AdminsgroupgrantsTier 0 Admins (owner)on Tier 0 Admins to 1 person directly

Tier 0 Admins is managed by PIM for Groups, but Sam Chen is a permanent owner. Convert the assignment to eligible. Open in portal

Membership
  • Tier 0 Admins (owner)Tier 0 Admins
    • Tier 0 Admins1 person direct
      • Sam Chen
People reached (1)
PersonThroughRemedy
Sam Chen
sam.chen@contoso.com
directTier 0 Admins is managed by PIM for Groups, but Sam Chen is a permanent owner. Convert the assignment to eligible. Open in portal

Azure RBAC

2 high2 mediumunder-counts

Permanent privileged Azure role assignments at any scope.

AZURE-PERMANENT

highA permanent privileged Azure role assignment2 findings
PrincipalRoleScopeHowRemedy
Alex Rivera
alex.rivera@contoso.com
Owner
Azure
Production
subscription
directRemove the permanent Owner assignment on Production and make Alex Rivera eligible for it in PIM. Open in portal
Deploy BotOwner
Azure
Production
subscription
directRemove the permanent Owner assignment on Production or make Deploy Bot eligible for it in PIM; PIM eligibility does not apply to workload identities. Open in portal

AZURE-PERMANENT

mediumA permanent privileged Azure role assignment1 group · 1 person
Cloud OpsgroupgrantsContributoron rg-payments to 1 person directly

Make the group's Contributor assignment on rg-payments eligible in PIM for Azure resources, or govern the group's membership with PIM for Groups. Open in portal

Membership
  • Contributorrg-payments
    • Cloud Ops1 person direct
      • Jordan Lee
People reached (1)
PersonThroughRemedy
Jordan Lee
jordan.lee@contoso.com
Cloud OpsJordan Lee holds Contributor on rg-payments permanently through Cloud Ops. Open in portal

Guests

1 high

Guests holding a permanent privileged role, directly or through a group.

GUEST-PERMANENT

highA guest holds a permanent privileged role1 finding
PrincipalRoleScopeHowRemedy
Priya Natarajan
priya.natarajan_fabrikam.com#EXT#@contoso.com guest
Security Administrator
Entra
Directory
directory
directGuest Priya Natarajan holds Security Administrator permanently. Guests should hold privileged roles only as eligible, if at all. Open in portal

Workload identities

2 info

Service principals and managed identities holding permanent privileged roles; PIM eligibility does not apply.

SP-PERMANENT

infoA service principal or managed identity holds a permanent privileged role2 findings
PrincipalRoleScopeHowRemedy
Deploy BotGlobal Administrator
Entra
Directory
directory
directDeploy Bot holds Global Administrator permanently. PIM eligibility does not apply to workload identities; review whether the workload identity needs the role at all, scope it down, or replace it with a narrower custom role. Open in portal
Deploy BotOwner
Azure
Production
subscription
directDeploy Bot holds Owner permanently. PIM eligibility does not apply to workload identities; review whether the workload identity needs the role at all, scope it down, or replace it with a narrower custom role. Open in portal

Unused eligibility

1 high4 medium

Eligibilities nobody exercises: never activated, dormant, or held by a principal that cannot use them.

ELIGIBLE-ORPHANED

high1 finding
PrincipalRoleScopeHowRemedy
Taylor Kim
taylor.kim@contoso.com
Security Administrator
Entra
Directory
directory
directTaylor Kim's account is disabled, and still holds this eligibility. Remove the eligibility, or move it behind an access review. Open in portal

ELIGIBLE-DORMANT

medium1 finding
PrincipalRoleScopeHowRemedy
Morgan Diaz
morgan.diaz@contoso.com
Global Administrator
Entra
Directory
directory
directLast activated 2026-03-20, 177 days ago; granted 620 days ago. Remove the eligibility, or move it behind an access review. Open in portal

ELIGIBLE-NEVER-ACTIVATED

medium3 findings
PrincipalRoleScopeHowRemedy
Casey Wong
casey.wong@contoso.com
Global Administrator
Entra
Directory
directory
directGranted 2025-01-01 (620 days ago) and never activated in the 180 days examined (since 2026-03-17). Remove the eligibility, or move it behind an access review. Open in portal
Jordan Lee
jordan.lee@contoso.com
Owner
Azure
Production
subscription
directGranted 2025-01-01 (620 days ago) and never activated in the 180 days examined (since 2026-03-17). Remove the eligibility, or move it behind an access review. Open in portal
Riley Park
riley.park@contoso.com
Global Administrator
Entra
Directory
directory
directGranted 2025-01-01 (620 days ago) and never activated in the 180 days examined (since 2026-03-17). Remove the eligibility, or move it behind an access review. Open in portal

Hygiene

1 medium5 low

Eligibilities without an end date and the Global Administrator count.

GA-COUNT

mediumFewer than 2 or more than 5 people can become Global Administrator1 finding
PrincipalRoleScopeHowRemedy
ContosoGlobal Administrator
Entra
Directory
directory
direct7 principals can become Global Administrator (permanent or eligible). Microsoft recommends at most five; move the rest to narrower roles. Open in portal

ELIGIBLE-NO-END

lowAn eligibility has no end date5 findings
PrincipalRoleScopeHowRemedy
Alex Rivera
alex.rivera@contoso.com
Tier 0 Admins (member)
Group
Tier 0 Admins
group
directGive the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal
Jordan Lee
jordan.lee@contoso.com
Global Administrator
Entra
Directory
directory
directGive the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal
Jordan Lee
jordan.lee@contoso.com
Owner
Azure
Production
subscription
directGive the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal
Morgan Diaz
morgan.diaz@contoso.com
Global Administrator
Entra
Directory
directory
directGive the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal
Riley Park
riley.park@contoso.com
Global Administrator
Entra
Directory
directory
directGive the eligibility an end date so it is reviewed, or cover it with an access review. Open in portal

Coverage

1 skipped

Which sources were read and which were skipped.

SourceStateWhat it means
Entra role assignmentsreadEvery active assignment and eligibility.
GroupsreadMembers of role-assigned groups, nested groups included.
PIM for GroupsreadActive and eligible memberships of PIM-managed groups.
Azure subscriptionsreadRole assignments in the subscriptions the account can read.
Azure management groupsskippedAzure management groups are not readable by this account; scanned subscriptions only.
PrincipalsreadNames, sign-in names and guest status.
Activation historyreadPIM activations in the lookback window, from the directory audit log and ARM's request history.

Appendix

Options, scopes requested, evidence ids

Options: all roles off; minimum severity info; ignored rules: none.

PIM activation history examined: 2026-03-17 to 2026-09-13 (180 days, Entra, Group, Azure). Directory audit logs are retained for 30 days by default, so the tenant may hold less than this window.

Read-only Microsoft Graph scopes requested: User.Read, RoleManagement.Read.Directory, PrivilegedAssignmentSchedule.Read.AzureADGroup, PrivilegedEligibilitySchedule.Read.AzureADGroup, GroupMember.Read.All, User.ReadBasic.All, AuditLog.Read.All. Nothing was written to the tenant.

This report contains personal data (names and sign-in names of people who hold roles). Handle it as you would any access review.

Evidence ids
RulePrincipal idAssignment idStartEndType
AZURE-PERMANENTu-alexra-alex-ownerClassic
AZURE-PERMANENTsp-deployra-deploy-ownerClassic
ELIGIBLE-ORPHANEDu-taylore-taylor-sec2025-01-012027-01-01Direct
ENTRA-GROUP-PERMANENTu-caseya-tier0-ga2025-01-01Assigned
ENTRA-GROUP-PERMANENTg-helpdeska-helpdesk-pra2025-01-01Assigned
ENTRA-GROUP-PERMANENTg-legacya-legacy-sec2025-01-01Assigned
ENTRA-GROUP-PERMANENTu-morgana-helpdesk-pra2025-01-01Assigned
ENTRA-GROUP-PERMANENTu-rileya-legacy-sec2025-01-01Assigned
ENTRA-GROUP-PERMANENTu-sama-tier0-ga2025-01-01Assigned
ENTRA-GROUP-PERMANENTg-tier0a-tier0-ga2025-01-01Assigned
ENTRA-USER-PERMANENTu-alexa-alex-ga2025-01-01Assigned
ENTRA-USER-PERMANENTu-priyaa-priya-sec2025-01-01Assigned
GROUP-MEMBER-PERMANENTu-samgp-sam-owner2025-01-01Assigned
GUEST-PERMANENTu-priyaa-priya-sec2025-01-01Assigned
AZURE-PERMANENTg-cloudopsra-cloudops-contribClassic
AZURE-PERMANENTu-jordanra-cloudops-contribClassic
ELIGIBLE-DORMANTu-morgane-morgan-ga2025-01-01Direct
ELIGIBLE-NEVER-ACTIVATEDu-caseye-casey-ga2025-01-012027-03-01Direct
ELIGIBLE-NEVER-ACTIVATEDu-jordanae-jordan-owner2025-01-01Schedule
ELIGIBLE-NEVER-ACTIVATEDu-rileye-riley-ga2025-01-01Direct
ENTRA-GROUP-NOT-ASSIGNABLEg-legacya-legacy-sec2025-01-01Assigned
ENTRA-GROUP-NOT-PIMg-helpdeska-helpdesk-pra2025-01-01Assigned
GA-COUNT5d3a9c1e-4f7b-4a2d-9e8c-0b6f1a2d3c4eglobal-administrator-count
ELIGIBLE-NO-ENDu-alexgp-alex-member2025-01-01
ELIGIBLE-NO-ENDu-jordane-jordan-ga2025-01-01Direct
ELIGIBLE-NO-ENDu-jordanae-jordan-owner2025-01-01Schedule
ELIGIBLE-NO-ENDu-morgane-morgan-ga2025-01-01Direct
ELIGIBLE-NO-ENDu-rileye-riley-ga2025-01-01Direct
SP-PERMANENTsp-deploya-deploy-ga2025-01-01Assigned
SP-PERMANENTsp-deployra-deploy-ownerClassic