M365 Changelog: Updates to the User Administrator role in Microsoft Entra Entitlement Management

MC536889 – On May 3, 2023, Microsoft will update Microsoft Entra Entitlement Management. This update will remove the ability for a user in the User Administrator role to manage Entitlement Management catalogs and access packages. If your organization has relied on users having the User Administrator role to manage Entitlement Management catalogs and access packages, add those users to the Identity Governance Administrator role. This ensures that those users can manage catalogs and access packages in Entitlement Management.

Microsoft wants to ensure minimal customer impact when it removes Entitlement Management permissions from the User Administrator role. By assigning admins the Identity Governance Administrator role, they will have the necessary permissions to continue managing catalogs and access packages.

In order to assign a user the Identity Governance Administrator role, follow these steps:

  1. Sign in to the Azure Active Directory admin center with Privileged Role Administrator permissions.
  2. Select Azure Active Directory > Roles and administrators.
  3. Select Identity Governance Administrator.
  4. Select Add assignments and add the users to whom you wish to assign this role.

You can also update these role assignments using Graph API. You can find more information on how to do that in our documentation.

Additionally, you can read more about roles and permissions here.

Microsoft greatly appreciates your understanding and cooperation as it releases this update. In the meantime, if you have any questions or concerns, please feel free to file a support case.

Additional information