You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/role-based-access-control/classic-administrators.md
+22-22Lines changed: 22 additions & 22 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,28 +1,28 @@
1
1
---
2
2
title: Azure classic subscription administrators
3
-
description: Describes how to prepare for the retirement of the Co-Administrator and Service Administrator roles and how to replace and remove these role assignments.
3
+
description: Describes the retirement of the Co-Administrator and Service Administrator roles and how to replace or remove these role assignments.
4
4
author: rolyon
5
5
manager: amycolannino
6
6
7
7
ms.service: role-based-access-control
8
8
ms.topic: how-to
9
-
ms.date: 04/08/2024
9
+
ms.date: 08/31/2024
10
10
ms.author: rolyon
11
11
ms.reviewer: bagovind
12
12
---
13
13
14
14
# Azure classic subscription administrators
15
15
16
16
> [!IMPORTANT]
17
-
> Classic resources and classic administrators will be [retired on August 31, 2024](https://azure.microsoft.com/updates/cloud-services-retirement-announcement/). Starting April 3, 2024, you won't be able to add new Co-Administrators. This date was recently extended. Replace or remove classic administrators and use Azure RBAC instead for fine-grained access control.
17
+
> Classic resources and classic administrators are [retired as of August 31, 2024](https://azure.microsoft.com/updates/cloud-services-retirement-announcement/). Replace or remove classic administrators and use Azure RBAC instead for fine-grained access control.
18
18
19
-
Microsoft recommends that you manage access to Azure resources using Azure role-based access control (Azure RBAC). However, if you're still using the classic deployment model, you'll need to use a classic subscription administrator role: Service Administrator and Co-Administrator. For information about how to migrate your resources from classic deployment to Resource Manager deployment, see [Azure Resource Manager vs. classic deployment](../azure-resource-manager/management/deployment-models.md).
19
+
Microsoft recommends that you manage access to Azure resources using Azure role-based access control (Azure RBAC). If you're still using the classic deployment model, you'll need to migrate your resources from classic deployment to Resource Manager deployment. For more information, see [Azure Resource Manager vs. classic deployment](../azure-resource-manager/management/deployment-models.md).
20
20
21
-
If you still have classic administrators, you should replace or remove these role assignments before the retirement date. This article describes how to prepare for the retirement of the Co-Administrator and Service Administrator roles and how to replace or remove these role assignments.
21
+
If you still have classic administrators, you should replace or remove these role assignments. This article describes the retirement of the Co-Administrator and Service Administrator roles and how to replace or remove these role assignments.
22
22
23
23
## Frequently asked questions
24
24
25
-
Will Co-Administrators and Service Administrator lose access after August 31, 2024?
25
+
Do Co-Administrators and Service Administrator lose access after August 31, 2024?
26
26
27
27
- Starting on August 31, 2024, Microsoft will start the process to remove access for Co-Administrators and Service Administrator.
28
28
@@ -40,15 +40,15 @@ What is the equivalent Azure role I should assign for Service Administrator?
40
40
41
41
Why do I need to migrate to Azure RBAC?
42
42
43
-
- Classic administrators will be retired. Azure RBAC offers fine grained access control, compatibility with Microsoft Entra Privileged Identity Management (PIM), and full audit logs support. All future investments will be in Azure RBAC.
43
+
- Classic administrators are retired. Azure RBAC offers fine grained access control, compatibility with Microsoft Entra Privileged Identity Management (PIM), and full audit logs support. All future investments will be in Azure RBAC.
44
44
45
45
What about the Account Administrator role?
46
46
47
47
- The Account Administrator is the primary user for your billing account. Account Administrator isn't being deprecated and you don't need to replace this role assignment. Account Administrator and Service Administrator might be the same user. However, you only need to replace or remove the Service Administrator role assignment.
48
48
49
49
What should I do if I lose access to a subscription?
50
50
51
-
- If you remove your classic administrators without having at least one Owner role assignment for a subscription, you will lose access to the subscription and the subscription will be orphaned. To regain access to a subscription, you must do the following:
51
+
- If you remove your classic administrators without having at least one Owner role assignment for a subscription, you will lose access to the subscription and the subscription will be orphaned. To regain access to a subscription, you can do the following:
52
52
53
53
- Follow steps to [elevate access to manage all subscriptions in a tenant](elevate-access-global-admin.md).
54
54
- Assign the Owner role at subscription scope for a user.
@@ -110,9 +110,9 @@ Follow these steps to list the number of Service Administrator and Co-Administra
110
110
111
111
---
112
112
113
-
## Prepare for Co-Administrators retirement
113
+
## Co-Administrators retirement
114
114
115
-
If you still have classic administrators, use the following steps to help you prepare for the Co-Administrator role retirement.
115
+
If you still have classic administrators, use the following steps to help you replace or remove Co-Administrator role assignments.
116
116
117
117
### Step 1: Review your current Co-Administrators
118
118
@@ -124,15 +124,15 @@ If you still have classic administrators, use the following steps to help you pr
124
124
125
125
### Step 2: Remove Co-Administrators that no longer need access
126
126
127
-
1. If user is no longer in your enterprise, [remove Co-Administrator](#remove-a-co-administrator).
127
+
1. If user is no longer in your enterprise, [remove Co-Administrator](#how-to-remove-a-co-administrator).
128
128
129
-
1. If user was deleted, but their Co-Administrator assignment wasn't removed, [remove Co-Administrator](#remove-a-co-administrator).
129
+
1. If user was deleted, but their Co-Administrator assignment wasn't removed, [remove Co-Administrator](#how-to-remove-a-co-administrator).
130
130
131
131
Users that have been deleted typically include the text **(User was not found in this directory)**.
132
132
133
133
:::image type="content" source="media/classic-administrators/user-not-found.png" alt-text="Screenshot of user not found in directory and with Co-Administrator role." lightbox="media/classic-administrators/user-not-found.png":::
134
134
135
-
1. After reviewing activity of user, if user is no longer active, [remove Co-Administrator](#remove-a-co-administrator).
135
+
1. After reviewing activity of user, if user is no longer active, [remove Co-Administrator](#how-to-remove-a-co-administrator).
136
136
137
137
### Step 3: Replace Co-Administrators with job function roles
138
138
@@ -144,7 +144,7 @@ Most users don't need the same permissions as a Co-Administrator. Consider a job
144
144
145
145
1. Follow steps to [assign a job function role to user](role-assignments-portal.yml).
### Step 4: Replace Co-Administrators with Owner role and constraints
150
150
@@ -154,15 +154,15 @@ Some users might need more access than what a job function role can provide. If
154
154
155
155
For example, assign the [Owner role at subscription scope with conditions](role-assignments-portal-subscription-admin.yml). If you have PIM, make the user [eligible for Owner role assignment](/entra/id-governance/privileged-identity-management/pim-resource-roles-assign-roles).
### Step 5: Replace Co-Administrators with Owner role
160
160
161
161
If a user must be an administrator for a subscription, assign the [Owner](built-in-roles.md#owner) role at subscription scope.
162
162
163
163
- Follow the steps in [Replace a Co-Administrator with Owner role](#replace-a-co-administrator-with-owner-role).
164
164
165
-
### Replace a Co-Administrator with Owner role
165
+
### How to replace a Co-Administrator with Owner role
166
166
167
167
The easiest way to replace a Co-Administrator role assignment with the [Owner](built-in-roles.md#owner) role at subscription scope is to use the **Remediate** steps.
168
168
@@ -182,7 +182,7 @@ The easiest way to replace a Co-Administrator role assignment with the [Owner](b
182
182
183
183
1. Select **Review + assign** to remove the Co-Administrator role assignment and assign the Owner role.
184
184
185
-
### Remove a Co-Administrator
185
+
### How to remove a Co-Administrator
186
186
187
187
Follow these steps to remove a Co-Administrator.
188
188
@@ -202,9 +202,9 @@ Follow these steps to remove a Co-Administrator.
202
202
203
203
:::image type="content" source="./media/classic-administrators/remove-coadmin.png" alt-text="Screenshot of message box when removing a Co-Administrator." lightbox="./media/classic-administrators/remove-coadmin.png":::
204
204
205
-
## Prepare for Service Administrator retirement
205
+
## Service Administrator retirement
206
206
207
-
If you still have classic administrators, use the following steps to help you prepare for Service Administrator role retirement. To remove the Service Administrator, you must have at least one user who is assigned the Owner role at subscription scope without conditions to avoid orphaning the subscription. A subscription Owner has the same access as the Service Administrator.
207
+
If you still have classic administrators, use the following steps to help you replace or remove Service Administrator role assignment. Before you remove the Service Administrator, you must have at least one user who is assigned the Owner role at subscription scope without conditions to avoid orphaning the subscription. A subscription Owner has the same access as the Service Administrator.
208
208
209
209
### Step 1: Review your current Service Administrator
210
210
@@ -230,9 +230,9 @@ Your Service Administrator might be a Microsoft account or a Microsoft Entra acc
230
230
231
231
1. If Service Administrator user is a Microsoft Entra account and you want this user to keep the same permissions, [replace the Service Administrator with Owner role](#replace-the-service-administrator-with-owner-role).
232
232
233
-
1. If you want to change the Service Administrator user to a different user, [assign the Owner role](role-assignments-portal.yml) to this new user at subscription scope without conditions. Then, [remove the Service Administrator](#remove-the-service-administrator).
233
+
1. If you want to change the Service Administrator user to a different user, [assign the Owner role](role-assignments-portal.yml) to this new user at subscription scope without conditions. Then, [remove the Service Administrator](#how-to-remove-the-service-administrator).
234
234
235
-
### Replace the Service Administrator with Owner role
235
+
### How to replace the Service Administrator with Owner role
236
236
237
237
The easiest way to replace the Service Administrator role assignment with the [Owner](built-in-roles.md#owner) role at subscription scope is to use the **Remediate** steps.
238
238
@@ -252,7 +252,7 @@ The easiest way to replace the Service Administrator role assignment with the [O
252
252
253
253
1. Select **Review + assign** to remove the Service Administrator role assignment and assign the Owner role.
254
254
255
-
### Remove the Service Administrator
255
+
### How to remove the Service Administrator
256
256
257
257
> [!IMPORTANT]
258
258
> To remove the Service Administrator, you must have a user who is assigned the [Owner](built-in-roles.md#owner) role at subscription scope without conditions to avoid orphaning the subscription. A subscription Owner has the same access as the Service Administrator.
0 commit comments