Which Role to assign MFA OATH tokens?

Christian Horn 26 Reputation points
2021-01-22T11:13:05.467+00:00

I'd like my supporters to be able to work with the OATH tokens blade (https://portal.azure.com/#blade/Microsoft_AAD_IAM/MultifactorAuthenticationMenuBlade/HardwareTokens/fromProviders/), i.e. upload CSVs and enable\disable devices.
Currently only global admin can do so and I haven't been able to figure out which role covers those rights or how to create a custom role for this particular feature. Of course, I can't give a bunch of L1 supporters Global Admin role just because of this simple routine task but also I have to delegate this eventually...

Thanks,
br
Chris

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,665 questions
{count} vote

4 answers

Sort by: Most helpful
  1. Marilee Turscak-MSFT 34,311 Reputation points Microsoft Employee
    2021-01-22T21:58:36.517+00:00

    To enable or disable a device you use either a global administrator or cloud device administrator role in Azure AD. https://learn.microsoft.com/en-us/azure/active-directory/devices/device-management-azure-portal

    Authentication administrator and Privileged authentication administrator roles can manage authentication methods but that doesn't seem to suit your particular needs.

    0 comments No comments

  2. Christian Horn 26 Reputation points
    2021-01-26T15:12:44.877+00:00

    I'm afraid Cloud Device Administrator doesn't work, it doesn't seem to cover those hardware tokens. At least not for write access, reading the settings is allowed.
    Global admin does work, of course, so I'd assume there's a Role Permission for this. Question is which one...

    0 comments No comments

  3. Marilee Turscak-MSFT 34,311 Reputation points Microsoft Employee
    2021-01-28T19:18:27.39+00:00

    You're right. For enabling or disabling a device you can be a global admin or cloud device admin but for assigning oath tokens you need to be a global admin.

    However, as this related discussion mentions, at least you are able to do it in bulk and there is a feedback item open on user voice for this ability to be available to other users.


  4. Jeroen i-Dienst 1 Reputation point
    2021-10-13T17:51:40.71+00:00

    Is there already a case open? and is there a status update? We are having the same issue...