Notifications
Announcements
No record found.
When I did a user report of the security roles I noticed that some users had the System Administrator security role assigned. I removed this role for each user because those users weren't eligible for that role.Some days later I noticed that the same thing happened to the same set of users so what I did was enable the Auditing for the security role entity and cleared their permissions.
Now that it happened again I checked the logs and saw that # CDSUserManagement is assigning the roles. Why is this happening and how can I stop this?
Regards
Hey Venjirai.
there are many reasons why this could be happening:
a) the tenant is using PIM and the affected users requested higher permissions (like Global Admin). As a result, this provides the uses that receive this higher Azure Role (Global Admin for example) with the System Administrator role on Dataverse.
b) Similar situation if the users have a higher role assigned in a permanent way (for example, Power Platform Administrator role in Azure)
The best advise would be to open a request to Microsoft for further investigation
Thanks for your reply, you led me to the right direction.
In Azure Active Directory I saw that those users had the role "Dynamics Administrator" assigned.
I removed those and I think this will have solved the problem.
Under review
Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.
As AI tools become more common, we’re introducing a Responsible AI Use…
We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…
These are the community rock stars!
Stay up to date on forum activity by subscribing.
Tom_Gioielli 70 Super User 2025 Season 2
Gerardo RenterÃa Ga... 33 Most Valuable Professional
Daniyal Khaleel 32 Most Valuable Professional