Skip to content

Commit 4ff34d3

Browse files
authored
Merge pull request #207115 from rolyon/rolyon-aadroles-sensitive-attributes-note
[Azure AD roles] Sensitive attributes note
2 parents c0a8902 + 7768414 commit 4ff34d3

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

articles/active-directory/roles/permissions-reference.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2383,6 +2383,12 @@ Usage Summary Reports Reader |   | :heavy_check_mark: | :heavy_check_mark:
23832383

23842384
\* A Global Administrator cannot remove their own Global Administrator assignment. This is to prevent a situation where an organization has 0 Global Administrators.
23852385

2386+
> [!NOTE]
2387+
> The ability to reset a password includes the ability to update the following sensitive attributes required for [self-service password reset](../authentication/concept-sspr-howitworks.md):
2388+
> - businessPhones
2389+
> - mobilePhone
2390+
> - otherMails
2391+
23862392
## Who can update sensitive attributes
23872393

23882394
Some administrators can update the following sensitive attributes for some users. All users can read these sensitive attributes.

0 commit comments

Comments
 (0)