How can I obtain this privileged administrator role: Policy Enforcement Role?

Xiuyu Zheng 20 Reputation points Microsoft Employee
2025-01-15T10:14:06.2266667+00:00

I want to create public IP in this resource group: ERNetwork - Microsoft Azure, but the policy SDOStdPolicyNetwork - Microsoft Azure deny my create a public IP. So I want to delete assignment, but I havn't permission. I find this privileged administrator role: Policy Enforcement Role have the permission: Microsoft.Authorization/PolicyAssignments/*. How can I get this privileged?  I found CoreIdentity seems have the PIM. And I also find your contact at here. Am I right? Can I request to join it?

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
871 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,479 questions
Microsoft Entra Private Access
Microsoft Entra Private Access
Microsoft Entra Private Access provides secure and deep identity-aware, Zero Trust network access to all private apps and resources.
78 questions
0 comments No comments
{count} votes

Accepted answer
  1. Sina Salam 16,526 Reputation points
    2025-01-15T17:33:42.32+00:00

    Hello Xiuyu Zheng,

    Welcome to the Microsoft Q&A and thank you for posting your questions here.

    Regarding your explanation, the first thing is to check if the Policy Enforcement Role is available and that you are eligible for it. You will need permissions like Microsoft.Authorization/PolicyAssignments/*.

    Secondly, if your organization uses Microsoft Entra Privileged Identity Management (PIM), you can request to activate this role. PIM helps manage, control, and monitor access within Azure AD, including privileged roles.

    Reach out to your Azure AD administrator or the person responsible for role assignments in your organization. They can grant you the necessary permissions.

    If your organization has a formal process for requesting roles, follow that process. This might involve submitting a request through a ticketing system or an internal portal.

    Also, once you have been granted eligibility for the role, you can activate it through the Azure portal. Here’s how: In you Azure Portal, Navigate to All services and select the scope (e.g., Management groups, Subscriptions, or Resource groups). From Access control (IAM) and find the role you want to activate. Click Activate and specify the start time, duration, and reason for activation - https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-eligible-activate

    Finally, after activation, verify that you have the necessary permissions to manage policy assignments.

    I hope this is helpful! Do not hesitate to let me know if you have any other questions.


    Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful.

    1 person found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Xiuyu Zheng 20 Reputation points Microsoft Employee
    2025-01-16T03:45:29.04+00:00

    Thanks, I got the answer, but I don't know who is our org Azure AD administrator.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.