question

PaulLizer avatar image
1 Vote"
PaulLizer asked PaulLizer answered

You are registered as a directory admin but do not have the necessary permissions to access the root management group.

The title says it all. I need additional rights to access the Tenant Root Group so that I can enable the setting for Require write permission for creating new management groups (see the screen capture).

My account is Global Admin, Owner, and User Access Administrator. Is there another administrator or permissions group that my account must be a member?

88207-image.png


azure-rbac
image.png (40.2 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

PaulLizer avatar image
1 Vote"
PaulLizer answered

The PowerShell method works as does using REST API.

https://docs.microsoft.com/en-us/azure/governance/management-groups/how-to/protect-resource-hierarchy#powershell-sample

The issue has been raised internally. When I am informed of its remediation, I will reply to this post.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MarileeTurscak-MSFT avatar image
0 Votes"
MarileeTurscak-MSFT answered PaulLizer edited

If the "Change default management group" button is disabled, either the management group being viewed isn't the root management group or you do not have the necessary permissions to alter the hierarchy settings.

The error you cited in the title often means that you might not have access to all subscriptions and management groups in your directory. One solution would to log on as a global admin and self elevate your access as described here. See related FAQ.

You would also set the below toggle to avoid that error:

88339-image.png



image.png (26.9 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hello, Marilee,

I appreciate taking the time to reply, however; that option is already enabled, and the issue persists.

I heard this may be a bug in the portal, but it can be updated via PowerShell. I will test the PowerShell method tomorrow and respond either way.

Respectfully,
Paul

0 Votes 0 ·