Unusual Activity Detected: Full Deny Assignment for User

Aid 0 Reputation points
2025-03-03T20:46:48.22+00:00

A full deny assignment was detected on ********* for user ******** at the root level. The deny assignment was added at the scope / for user ***********. What could be the implications of this unusual activity?

Though i have marked my account ( service administrator ) as Safe in the Azure Identity protector it's still saying that this root level full deny is inherited.

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
886 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Sanoop M 1,245 Reputation points Microsoft External Staff
    2025-03-04T00:53:51.4933333+00:00

    Hello @Aid,

    Thank you for posting your query on Microsoft Q&A.

    Based on the error message, I understand that your user account has been added to a Deny Assignments list at the root level.

    Deny assignments block users from performing specific Azure resource actions even if a role assignment grants them access.

    Important

    You can't directly create your own deny assignments. Deny assignments are created and managed by Azure to protect resources.

    Prerequisites

    To get information about a deny assignment, you must have:

    • Microsoft.Authorization/denyAssignments/read permission, which is included in most Azure built-in roles.

    List deny assignments in the Azure portal

    Follow these steps to list deny assignments at the subscription or management group scope.

    1. In the Azure portal, open the selected scope, such as resource group or subscription.
    2. Select Access control (IAM).
    3. Select the Deny assignments tab (or select the View button on the View deny assignments tile). If there are any deny assignments at this scope or inherited to this scope, they'll be listed as mentioned in the below Screenshot. Screenshot of Access control (IAM) page and Deny assignments tab that lists deny assignments at the selected scope. 4.To display additional columns, select Edit Columns. Screenshot of deny assignments columns pane that shows how to add columns to list of deny assignments.5. Add a checkmark to any of the enabled items and then select OK to display the selected columns.

    Delete deny assignments in the Azure portal

    1.Please make sure that you are having a role with enough privileges, like Owner or User Access Administrator.

    2.Under the Deny assignments tab, select the affected user account and then delete or Remove the affected user account from Deny assignments list.

    For additional details, please refer to the below document for your reference.

    List Azure deny assignments - Azure RBAC | Microsoft Learn

    I hope this above information provided is helpful. Please feel free to reach out if you have any further questions.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.