MC358528 – (Updated) Update on who can manage sensitive attributes of user objects (archived)

cloudscout.one Icon

check before: 2022-04-28

Product:

Azure Active Directory

Platform:

World tenant, Online

Status:

Change type:

Admin impact, Updated message

Links:

Details:

Updated July 13, 2022: We have updated the rollout timeline below. Thank you for your patience.
Today, there are several user attributes that are considered sensitive, and we will be simplifying this model.
Some rely on Global Admins (GA) to be able to manage them for all users (admins and non-admins).
Others don’t have a Global Admins dependency but the set of admin roles that can manage them and for whom is not consistent.
[When this will happen:]
We will begin rolling this out in early June and expect to complete rollout by early August (previously late June).

Change Category:
XXXXXXX ...

Scope:
XXXXXXX ...

Release Phase:

Created:
2022-04-14

updated:
2022-08-27

the free basic plan is required to see all details. Sign up here


A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.


changes*

DatePropertyoldnew
2022-08-27MC prepareWe will align the behavior of managing user attributes with that mentioned above. So, some older roles that were also allowed to manage user attributes (for ex - Directory Writer) will no longer work. Please work with your Privileged Role Admin or Global Admin if new role assignments are needed to avoid any impact on your business operations.
https://docs.microsoft.com/azure/active-directory/roles/permissions-reference#password-reset-permissions
We will align the behavior of managing user attributes with that mentioned above. So, some older roles that were also allowed to manage user attributes (for ex - Directory Writer) will no longer work. Please work with your Privileged Role Admin or Global Admin if new role assignments are needed to avoid any impact on your business operations.
ps://docs.microsoft.com/azure/active-directory/roles/permissions-reference#password-reset-permissi
2022-07-15MC MessagesToday, there are several user attributes that are considered sensitive, and we will be simplifying this model.
Some rely on Global Admins (GA) to be able to manage them for all users (admins and non-admins).
Others don’t have a Global Admins dependency but the set of admin roles that can manage them and for whom is not consistent.
[When this will happen:]
We will begin rolling this out in early June and expect to complete rollout late June.
Updated July 13, 2022: We have updated the rollout timeline below. Thank you for your patience.
Today, there are several user attributes that are considered sensitive, and we will be simplifying this model.
Some rely on Global Admins (GA) to be able to manage them for all users (admins and non-admins).
Others don’t have a Global Admins dependency but the set of admin roles that can manage them and for whom is not consistent.
[When this will happen:]
We will begin rolling this out in early June and expect to complete rollout by early August (previously late June).
2022-07-15MC TitleUpdate on who can manage sensitive attributes of user objects(Updated) Update on who can manage sensitive attributes of user objects
2022-07-15MC Last Updated04/14/2022 00:48:442022-07-14T23:25:21Z
2022-07-15MC MessageTagNamesAdmin impactUpdated message, Admin impact
2022-07-15MC End Time08/05/2022 09:00:002022-09-05T09:00:00Z

*starting April 2022

Last updated 4 weeks ago

Login to your account

Welcome Back, We Missed You!