Azure RBAC vs Microsoft Entra roles: why the Owner can't reset a password

Azure has two separate role systems. Azure roles control resources; Microsoft Entra roles control the directory. Scopes and inheritance, Owner vs Contributor vs User Access Administrator, elevate access, and three traps.

By Tony Rough

  • AZ-104
  • SC-500
  • AZ-305
  • identity
  • governance
  • exam traps

Two questions catch people out:

Because Azure has two separate role systems, and by default neither grants anything in the other.

Two systems

Azure roles (Azure RBAC) Microsoft Entra roles
Control Azure resources: management groups, subscriptions, resource groups, resources The directory: users, groups, app registrations, licences, domains
Assigned at Management group, subscription, resource group or single resource The whole tenant, an administrative unit or a single object
Where you see them Access control (IAM) on any scope Roles and administrators in the Entra admin center

Azure roles: scope and inheritance

An Azure role assignment is three things: who (a user, group, service principal or managed identity), what (a role definition) and where (a scope). Assignments are inherited downwards: Contributor on a resource group applies to everything inside it, and an assignment on a management group applies to every subscription beneath it.

The roles that matter most:

Role Manage resources Assign roles
Owner ✓ ✓
Contributor ✓ ✗
Reader read only ✗
User Access Administrator read only ✓
Role Based Access Control Administrator read only ✓, and can be limited by conditions

The rule of thumb: assign the least powerful role at the narrowest scope that does the job.

Microsoft Entra roles

Entra roles manage the directory itself:

Least privilege applies here too: pick the narrowest role, and scope it to an administrative unit when someone should only manage part of the organisation.

The one bridge: elevate access

A Global Administrator can turn on Access management for Azure resources (Microsoft Entra ID → Properties). That elevates their access: they’re given User Access Administrator at the root scope (/), which covers every management group and subscription in the tenant. From there they can grant themselves or others whatever Azure roles are needed.

It’s a recovery tool (for example, regaining access to a subscription whose owners have left) and it applies only to the person who switches it on. Microsoft’s guidance is to switch it off again once the change is made.

Three traps

  1. Contributor can’t grant access. Someone who has to assign roles needs Owner, User Access Administrator or Role Based Access Control Administrator.
  2. A subscription Owner isn’t a directory admin. Creating users, resetting passwords and assigning licences all need a Microsoft Entra role.
  3. The classic administrator roles are retired. Co-Administrator and Service Administrator no longer exist; any answer that relies on them is out of date.

Pick it in five seconds

You need… Choose
Rights over Azure resources (VMs, storage, networks) An Azure role, at the narrowest scope
Rights over users, groups, passwords or licences A Microsoft Entra role
Manage resources, but not access Contributor
Manage access, but not resources User Access Administrator
A Global Administrator locked out of a subscription Elevate access, then switch it off

Go deeper

Azure RBAC is chapter 2 of the AZ-104 study guide, with Entra users and groups in chapter 1. Entra roles versus Azure RBAC and elevate access are covered in the governance chapter (chapter 4) of the SC-500 study guide, and identity design in chapter 1 of the AZ-305 study guide. Facts checked against Microsoft Learn on 4 October 2026.

The books in this post

More from the blog

All posts