Granted Microsoft.Authorization/* actions, this Azure role handles role assignments and management locks, yet it can't write tags or manage any other resources. For creating or removing locks, no less-privileged role suffices.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500SC-200AZ-400MD-102
Each book explains User Access Administrator in context, with comparison tables and the common traps.
Terms in this definition
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- Image tagging
An Image Analysis feature producing single-word tags, each with a confidence score, for actions, scenery, objects and living things in an image.
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES.
Related terms
- Elevate access
A toggle under Entra Properties; when the signed-in Global Administrator switches it on, that one admin becomes User Access Administrator at root scope (/).
- Microsoft.Authorization
Namespace of the resource provider handling policy, resource locks, role definitions and role assignments. Only roles such as Owner and User Access Administrator hold roleAssignments/write.
- MS-PIM
To manage Azure resource roles, PIM works through this service principal, which therefore requires User Access Administrator at subscription or management group level.
- Role Based Access Control Administrator
Role able to add and remove role assignments (
roleAssignments/write) but not to manage resources. Along with Owner and User Access Administrator, it is one of the roles that can assign roles.