Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| azure:az-104_2024:identity_and_access_management [2024/10/16 16:55] – [Global Admin Elevated Access] mmuze | azure:az-104_2024:identity_and_access_management [2025/11/29 17:48] (current) – mmuze | ||
|---|---|---|---|
| Line 121: | Line 121: | ||
| ====== Global Admin Elevated Access ====== | ====== Global Admin Elevated Access ====== | ||
| + | * [[https:// | ||
| * As a Global Administrator in Microsoft Entra ID, you might not have access to all subscriptions and management groups in your directory. | * As a Global Administrator in Microsoft Entra ID, you might not have access to all subscriptions and management groups in your directory. | ||
| * There is a setting on the Entra Id tenant/ | * There is a setting on the Entra Id tenant/ | ||
| - | * This setting gives the user the User Access Administrator role for the root management group that is inherited by all subscriptions. | + | * This setting gives the user the User Access Administrator role for the root scope that is inherited by all management groups/subscriptions. |
| * Although it's a per-user settings it is enabled from the tenant blade, not the user properties blade. | * Although it's a per-user settings it is enabled from the tenant blade, not the user properties blade. | ||
| + | * Also, it results in an Azure role being assigned to the user, not a Entra Id/ | ||
| + | |||
| + | ====== Multi-factor Authentication (MFA) ====== | ||
| + | * Conditional Access based MFA is also call Per-Authentication MFA in contrast to Per-User MFA. | ||
| + | |||
| + | ====== Conditional Access ====== | ||
| + | * [[https:// | ||
| + | |||