MC358528 – (Updated) Update on who can manage sensitive attributes of user objects (archived)

cloudscout.one Icon

check before: 2022-04-28

Product:

Azure Active Directory, Entra, Entra ID

Platform:

World tenant, Online

Status:

Change type:

Admin impact, Updated message

Links:

Details:

Updated July 13, 2022: We have updated the rollout timeline below. Thank you for your patience.
Today, there are several user attributes that are considered sensitive, and we will be simplifying this model.
Some rely on Global Admins (GA) to be able to manage them for all users (admins and non-admins).
Others don’t have a Global Admins dependency but the set of admin roles that can manage them and for whom is not consistent.
[When this will happen:]
We will begin rolling this out in early June and expect to complete rollout by early August (previously late June).

Change Category:
XXXXXXX ... free basic plan only

Scope:
XXXXXXX ... free basic plan only

Release Phase:

Created:
2022-04-14

updated:
2022-08-27

Task Type

XXXXXXX ... free basic plan only

Docu to Check

XXXXXXX ... free basic plan only

MS How does it affect me

XXXXXXX ... free basic plan only

MS Preperations

XXXXXXX ... free basic plan only

MS Urgency

XXXXXXX ... free basic plan only

MS workload name

XXXXXXX ... free basic plan only

More Info URL

XXXXXXX ... free basic plan only

** AI generated content. This information is not reliable.

the free basic plan is required to see all details. Sign up here


change history

DatePropertyoldnew
2022-08-27MC prepareWe will align the behavior of managing user attributes with that mentioned above. So, some older roles that were also allowed to manage user attributes (for ex - Directory Writer) will no longer work. Please work with your Privileged Role Admin or Global Admin if new role assignments are needed to avoid any impact on your business operations.
https://docs.microsoft.com/azure/active-directory/roles/permissions-reference#password-reset-permissions
We will align the behavior of managing user attributes with that mentioned above. So, some older roles that were also allowed to manage user attributes (for ex - Directory Writer) will no longer work. Please work with your Privileged Role Admin or Global Admin if new role assignments are needed to avoid any impact on your business operations.
ps://docs.microsoft.com/azure/active-directory/roles/permissions-reference#password-reset-permissi
2022-07-15MC MessagesToday, there are several user attributes that are considered sensitive, and we will be simplifying this model.
Some rely on Global Admins (GA) to be able to manage them for all users (admins and non-admins).
Others don’t have a Global Admins dependency but the set of admin roles that can manage them and for whom is not consistent.
[When this will happen:]
We will begin rolling this out in early June and expect to complete rollout late June.
Updated July 13, 2022: We have updated the rollout timeline below. Thank you for your patience.
Today, there are several user attributes that are considered sensitive, and we will be simplifying this model.
Some rely on Global Admins (GA) to be able to manage them for all users (admins and non-admins).
Others don’t have a Global Admins dependency but the set of admin roles that can manage them and for whom is not consistent.
[When this will happen:]
We will begin rolling this out in early June and expect to complete rollout by early August (previously late June).
2022-07-15MC TitleUpdate on who can manage sensitive attributes of user objects(Updated) Update on who can manage sensitive attributes of user objects
2022-07-15MC Last Updated04/14/2022 00:48:442022-07-14T23:25:21Z
2022-07-15MC MessageTagNamesAdmin impactUpdated message, Admin impact
2022-07-15MC End Time08/05/2022 09:00:002022-09-05T09:00:00Z

Last updated 2 years ago ago

Leave a Reply

Share to MS Teams

Login to your account

Welcome Back, We Missed You!