A toggle under Entra Properties; when the signed-in Global Administrator switches it on, that one admin becomes User Access Administrator at root scope (/).
Also called Access management for Azure resources.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-104SC-500AZ-900SC-900SC-300ALZ
Each book explains Elevate access in context, with comparison tables and the common traps.
Terms in this definition
- Global Administrator
The Microsoft Entra role with complete control over the directory. On its own it gives no rights over Azure resources; the holder must elevate access to manage all subscriptions first.
- User Access Administrator
Granted Microsoft.Authorization/* actions, this Azure role handles role assignments and management locks, yet it can't write tags or manage any other resources. For creating or removing locks, no less-privileged role suffices.
- Scope
Where an access or policy assignment takes effect. It can be set on a single resource, a resource group, a subscription or a management group, and settings flow down from higher levels.