thub.users.profile.tabs.comments.personalized


@JamesHamil-MSFT looks like it was an outage for 24hrs or so. Waiting on MS to provide root cause, via internal support ticket. Will close this post. Thanks.

Yes in correct directory and subscription. I have GA and have access to all management groups and subs. I have also logged in with the EA Account into the portal and gone to Subscription > Add subscription and same error as above. Some how the EA accout has been unlinked to the Billing Account... even if a run PS to create a subscription using EA credentials i doesn't like it @JamesHamil-MSFT

Thanks for testing and appreciated, our accounts are Sync'd from OnPrem. I've not cleared any Authentication Methods, it was just an export from the blade. That's when I noticed from my screenshot, that some users were SSPR Registered and SSPR Enabled - but methodsRegistered blank.

@AndyDavid Strange why MS would set this as an Enabled if not values have been populated. Ideally it would be good to show as Not Enabled

The Authentication methods | User registration details blade could be better cleaned up as the columns, don't give enough detail or clear information. i.e. some users may have started the SSPR\MFA process, but the Methods Registered for that user is blank. Even though SSPR shows registered. Can something like, not completed field be added.

@SagarGohil how is the export file set? and are you elevating any Azure role?

@stan thanks for the advice, all logs are on and pulling into log analytics. What I wanted to know specifically as well. Is there an example Kusto query that shows only PIM role assignments etc. At moment running the audit logs, shows me everything. I just want the PIM values. Thanks

Thanks, looks like that has worked, i was mssing one line.
One other question I have, when i try to add a Security Group, for example to Quarantine Administrator using

Add-Rolemember -Identity "Quarantine Administrator" -member TestGroup

and then I do Get-RoleGroupMember -Identity "Quarantine Administrator" it shows up as

Name Receipet type


c841c00c Group

Just wondering what is the number? is that the group?
Thanks

@michev

Hi, when I open a Role Reviews, the last column shows when, what I believe the user last logged onto the portal i.e. portal.azure.com. If I click on Audit Details it doesn't show me more info, unless access is elevated. Just wondering why can't last column show, when user last PIM'ed the Role? I assume that would be more reliable data. @JamesTran-MSFT

46873-screenshot-20201210-084152-gallery.jpg


46525-20201209-091528.jpg





Please see screenshot, this is greyed out. I've used Priv Role Admin and GA and still not able to toggle on. I set all reviews with this on, a few have flipped back.
@JamesHamil-MSFT