Skip to content

Commit 1046bdd

Browse files
committed
PIM solution
1 parent e279952 commit 1046bdd

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

articles/role-based-access-control/troubleshooting.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -271,6 +271,10 @@ If you want to cancel your subscription, see [Cancel your Azure subscription](..
271271

272272
You're allowed to remove the last Owner (or User Access Administrator) role assignment at subscription scope, if you're a Global Administrator for the tenant. In this case, there's no constraint for deletion. However, if the call comes from some other principal, then you won't be able to remove the last Owner role assignment at subscription scope. To override this default behavior, enable the "Allow removal of the last subscription Owner role assignment" feature in the Azure portal.
273273

274+
**Solution 3**
275+
276+
If you use [Microsoft Entra Privileged Identity Management (PIM)](/entra/id-governance/privileged-identity-management/pim-configure) and you are eligible for the Owner (or User Access Administrator) role, you can [activate](/entra/id-governance/privileged-identity-management/pim-resource-roles-activate-your-roles) your Owner (or User Access Administrator) role assignment temporarily, remove the last Owner role assignment, and then deactivate or let your role assignment expire.
277+
274278
### Symptom - Role assignment isn't moved after moving a resource
275279

276280
**Cause**

0 commit comments

Comments
 (0)