iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Granting access to an Azure root management group is a tenant-wide operation. A role assignment made there is inherited by every child management group, subscription, resource group, and resource in the Microsoft Entra directory.
The account performing the grant normally needs Azure RBAC permission to create role assignments at the root scope. A Microsoft Entra Global Administrator does not automatically have that permission. The administrator must first elevate access, or receive a suitable Azure role assignment through another authorized administrator.
What the Azure root management group is
Every Microsoft Entra directory has one top-level management group. Its default display name is Tenant root group, while its management-group ID is the Microsoft Entra tenant ID. The root management group cannot be moved or deleted.
The root management group sits above the rest of the Azure management-group hierarchy:
#1 Best Overall
Tenant root group
├── Production management group
│ ├── Subscription A
│ └── Subscription B
└── Development management group
└── Subscription C
An Azure RBAC assignment at the root scope flows down this hierarchy. For example, assigning Reader at the root can provide read access throughout the directory, while assigning Owner can provide broad control, including the ability to assign roles and manage policy operations inherited by descendants.
Important distinction: Global Administrator is not Azure Owner
Microsoft Entra directory roles and Azure RBAC roles are separate permission systems. Being a Microsoft Entra Global Administrator does not automatically grant access to all Azure subscriptions or management groups. Likewise, being an Owner of an individual subscription does not automatically grant access to the tenant root management group.
No user has default management access to the root management group—not even a Global Administrator or an Azure subscription Owner. A Global Administrator can, however, elevate their own Azure access. That operation assigns the signed-in user the Azure RBAC User Access Administrator role at the root scope /.
User Access Administrator allows the user to view resources and assign Azure roles across the subscriptions and management groups associated with the tenant. It does not itself make the user an Owner of the root management group.
Before you start
- Confirm that you are working in the correct Microsoft Entra tenant.
- Make sure the account is assigned the Microsoft Entra Global Administrator role if you plan to use elevation.
- If Global Administrator is activated through Microsoft Entra Privileged Identity Management (PIM), activate it before elevating access.
- Decide what role the recipient actually needs. Prefer the least-privileged role and the narrowest practical scope.
- Have the tenant ID available. For the root management group, the ID is the tenant ID—not the display name Tenant root group.
Use root scope sparingly. A root-level role assignment affects the entire directory hierarchy. Microsoft recommends limiting root-scope user-access and policy assignments to cases where they are genuinely required.
Step 1: Elevate your own access in the Azure portal
Only a user assigned the Microsoft Entra Global Administrator role can use this elevation control. The setting is per-user; enabling it does not elevate every Global Administrator in the tenant.
- Sign in to the Azure portal as a Global Administrator.
- Open Microsoft Entra ID.
- Under Manage, select Properties.
- Under Access management for Azure resources, set the toggle to Yes.
- Select Save.
- Sign out of the Azure portal and sign back in to refresh your permissions.
After elevation, Azure creates a root-scope assignment for your signed-in account:
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11| Property | Value |
|---|---|
| Role | User Access Administrator |
| Scope | / |
| Applies to | Azure subscriptions and management groups associated with the tenant |
This is a temporary administrative mechanism. It is not the same as assigning the Owner role to yourself.
Step 2: Assign a role to a user or group at the root
Once your access has refreshed, use Azure RBAC to grant the required role.
- In the Azure portal, search for and open Management groups.
- Select Tenant root group.
- Select Access control (IAM).
- Open the Role assignments tab.
- Select Add > Add role assignment.
- On the Role tab, select the required role and select Next.
- On the Members tab, choose User, group, or service principal.
- Select Select members, choose the user or group, and select Select.
- Select Next through any applicable Conditions and Assignment type tabs.
- On Review + assign, select Review + assign.
Which role should you choose?
The role picker separates roles into categories such as Job function roles and Privileged administrator roles. Common choices include:
| Role | Use it when | Scope warning |
|---|---|---|
| Reader | The person only needs to view the hierarchy and resources. | Read access is inherited throughout the root hierarchy. |
| Management Group Contributor | The person needs to manage management-group objects. | This is not equivalent to Owner for all inherited Azure resource permissions. |
| Contributor | The person needs to manage Azure resources but should not assign access. | At root scope, the assignment affects descendants. |
| User Access Administrator | The person needs to manage Azure role assignments. | This is a highly sensitive access-management role. |
| Role Based Access Control Administrator | The person needs to manage Azure RBAC assignments without broader Owner permissions. | Review the role’s current permissions before assigning it at root. |
| Owner | The person requires broad control, including role assignment and policy-related administration. | This is one of the broadest assignments possible and should be reserved for a clear administrative need. |
If the recipient needs access only to one subscription or management group, assign the role at that narrower scope instead of the root.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Why “Add role assignment” might be disabled
To create an Azure role assignment, the operator needs Microsoft.Authorization/roleAssignments/write. This permission is included in roles such as User Access Administrator and Role Based Access Control Administrator.
If Add role assignment is disabled after you sign back in, check the following:
- The Global Administrator elevation was saved successfully.
- You signed out and back in after enabling elevation.
- You opened Tenant root group, not a different management group.
- Your current directory and subscription filters point to the intended tenant.
- You are using the same user account that performed the elevation.
Grant access with Azure CLI
You can elevate the signed-in Global Administrator with Azure CLI by calling the Azure management REST endpoint:
az rest --method post --url "/providers/Microsoft.Authorization/elevateAccess?api-version=2016-07-01"
After elevation, grant a role at a management-group scope:
az role assignment create
--assignee "{assignee}"
--role "{roleNameOrId}"
--scope "/providers/Microsoft.Management/managementGroups/{managementGroupName}"
For the root management group, replace {managementGroupName} with the Microsoft Entra tenant ID:
Rank #3
az role assignment create
--assignee "user@example.com"
--role "Owner"
--scope "/providers/Microsoft.Management/managementGroups/{tenantId}"
Do not use Tenant root group in this command. That is the display name, not the root management-group ID.
For a service principal, use its directory object ID where required, not its application or client ID. A newly created service principal can also encounter directory replication delays. In that situation, specify the object ID and principal type explicitly:
az role assignment create
--assignee-object-id "{servicePrincipalObjectId}"
--assignee-principal-type ServicePrincipal
--role "{roleNameOrId}"
--scope "/providers/Microsoft.Management/managementGroups/{tenantId}"
Verify the elevated assignment
To check the root assignment created by elevation, run:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →az role assignment list
--role "User Access Administrator"
--scope "/"
The expected result has:
scopeequal to/roleDefinitionNameequal toUser Access Administrator
With Azure PowerShell, use:
Get-AzRoleAssignment | where {
$_.RoleDefinitionName -eq "User Access Administrator" `
-and $_.SignInName -eq "<username@example.com>" `
-and $_.Scope -eq "/"
}
Azure REST API option
The equivalent elevation request is:
POST https://management.azure.com/providers/Microsoft.Authorization/elevateAccess?api-version=2016-07-01
Microsoft documents API version 2016-07-01 or later for elevation. The documented minimum for listing and removing role assignments is 2015-07-01 or later. The caller must still be an eligible Global Administrator and authenticated to the correct tenant.
Remove access after the work is complete
For temporary elevation, remove it as soon as the administrative task is finished.
Remove elevation in the portal
- Sign in as the same user who elevated access.
- Go to Microsoft Entra ID > Manage > Properties.
- Set Access management for Azure resources to No.
- Save the change.
- Sign out.
The setting must be changed by the user whose account was elevated. If Global Administrator was activated through PIM, Microsoft recommends setting this toggle to No before deactivating the Global Administrator assignment. Deactivating the PIM assignment does not automatically change the elevation setting to No.
Some tenants may show a Manage elevated access users link below the elevation setting. Microsoft is deploying this capability in stages. Where available, select the users and choose Remove.
Remove the root assignment with Azure CLI
az role assignment delete
--assignee username@example.com
--role "User Access Administrator"
--scope "/"
Remove it with Azure PowerShell
Remove-AzRoleAssignment `
-SignInName <username@example.com> `
-RoleDefinitionName "User Access Administrator" `
-Scope "/"
The root-scope User Access Administrator assignment created by elevation cannot normally be removed through the ordinary removal workflow on the Access control (IAM) page. Use the elevation toggle, Azure CLI, Azure PowerShell, or the REST API instead.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Review elevation in audit logs
To review elevation and removal events in the Azure portal:
- Open Microsoft Entra ID.
- Go to Monitoring > Audit logs.
- Set Service to Azure RBAC (Elevated Access).
- Select Apply.
Relevant entries include:
User has elevated their access to User Access Administrator for their Azure ResourcesThe role assignment of User Access Administrator has been removed from the user
Microsoft currently labels these Microsoft Entra directory-audit-log entries as preview. The preview has no service-level agreement and is not recommended as the sole audit mechanism for production workloads.
FAQ
Does a Global Administrator automatically have access to the Azure root management group?
No. Microsoft Entra Global Administrator and Azure RBAC are independent. The Global Administrator must elevate access or receive an Azure RBAC assignment from an authorized administrator.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsIs the root management-group name the same as its ID?
No. The default display name is Tenant root group. The management-group ID is the Microsoft Entra tenant ID.
Does subscription Owner access control the root management group?
No. Owner at subscription scope does not automatically provide access to the tenant root-management-group scope.
What is the safest role to assign at root scope?
Use the least-privileged role that meets the requirement. Reader is appropriate for viewing. Use Management Group Contributor for management-group administration where suitable, and avoid Owner or user-access roles unless the recipient genuinely needs their broad permissions.
Can I assign access to a group instead of an individual?
Yes. In the portal’s Members step, choose User, group, or service principal, then select the group. Group-based assignment can simplify administration, but membership in a root-scope group must be tightly controlled.
Free tools Windows power users keep installed
One-click scans. No signup required.
Why can’t I remove the elevated assignment from Access control (IAM)?
The special root-scope User Access Administrator assignment created by elevation is not removed through the ordinary IAM removal workflow. Turn off Access management for Azure resources, or remove the assignment with Azure CLI, PowerShell, or the REST API.
The Bottom Line
To grant access to an Azure root management group, a Global Administrator must first enable Access management for Azure resources under Microsoft Entra ID > Properties, save, and sign in again. Then open Management groups > Tenant root group > Access control (IAM) and create the narrowest suitable role assignment.
Remember that root assignments are inherited across the entire tenant hierarchy. Verify the assignment, document why it exists, and remove temporary elevation or unnecessary root-level roles when the work is complete.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →

