Microsoft Entra ID Governance
Fundamentals

Pim For Groups

In brief

The role-assignable groups description now includes members and owners, including eligible members and owners who have not activated their assignments.

What Entra admins need to know

Administrators should use the updated wording when interpreting the protections for role-assignable groups. No action is required.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Role-assignable groups benefit from extra protections compared to non-role-assignable groups:

  • Role-assignable groups - only the Global Administrator, Privileged Role Administrator, or the group Owner can manage the group. Also, no other users can change the credentials of the users who are (active) members and owners of the group.group, including eligible members and owners who haven't activated yet. This feature helps prevent an admin from elevating to a higher privileged role without going through a request and approval procedure.
  • Non-role-assignable groups - various Microsoft Entra roles can manage these groups – that includes Exchange Administrators, Groups Administrators, User Administrators. Also, various Microsoft Entra roles can change the credentials of the users who are (active) members of the group – that includes Authentication Administrators, Helpdesk Administrators, User Administrators.

To learn more about Microsoft Entra built-in roles and their permissions, see Microsoft Entra built-in roles.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…