Entitlement Management Delegate
In brief
The entitlement management delegation documentation removes a note about access package assignment managers being unable to bypass approval requirements when directly assigning identities.
What Entra admins need to know
Administrators should no longer rely on the removed note when interpreting assignment manager approval behavior.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Required roles to add resources to a catalog
A Global Administrator can add or remove any group (cloud-created security groups or cloud-created Microsoft 365 Groups), application, or SharePoint Online site in a catalog.
@@ -122,9 +122,6 @@ To determine the least privileged role for a task, you can also reference [Least > [!NOTE] > Entitlement management roles authorize actions within entitlement management, but they don't by themselves change tenant-wide access settings for the Microsoft Entra admin center. If the **Restrict access to Microsoft Entra administration portal** user setting is enabled, a delegated user might need to be allowed to access the Microsoft Entra admin center before they can complete admin center tasks such as viewing, adding, removing, or reprocessing access package assignments. For more information about this setting, see [Default user permissions](../fundamentals/users-default-permissions.md). -> [!NOTE]-> Identities that have been assigned the Access package assignment manager role will no longer be able to bypass approval settings when directly assigning an identity if the access package policy requires approval. If you have a scenario in which you need to bypass approval, we recommend creating a second policy on the access package that does not require approval and is scoped only to identities who need access.- ## Required roles to add resources to a catalog A Global Administrator can add or remove any group (cloud-created security groups or cloud-created Microsoft 365 Groups), application, or SharePoint Online site in a catalog. 