An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
Hello Shekinah Farms Incorporated
Azure subscription permissions and Microsoft Entra directory permissions are separate.
Being Owner/Contributor at the Azure subscription level does not grant permission to create or manage Microsoft Entra users. Microsoft documents User Administrator as the least-privileged role required to create users.
Check Microsoft Entra admin center → Entra ID → Roles & admins → My roles.
If the account previously had the required role and it was removed:
- A Privileged Role Administrator or Global Administrator can assign the required Entra role again.
- If the role is managed through PIM and you are only eligible, activate it first.
- If there is no accessible Global Administrator/Privileged Role Administrator remaining, this becomes a tenant-lockout scenario. It cannot be repaired using Azure subscription Owner permissions. Microsoft Support must verify tenant ownership and involve the Data Protection/Tenant Recovery team. Microsoft staff have used this recovery path for similar tenant-lockout cases.
So if the only problem is creating users, assigning User Administrator is preferable to restoring Global Administrator unless broader directory administration is actually required.
Official documentation:
Azure roles vs. Microsoft Entra roles