If a user want to assign a policy to the tenant root management group, what role can do this?

Shaojun Qin 100 Reputation points
2024-04-24T12:40:39.39+00:00

Global administrator role?

Owner role of the subscription?

Azure Role-based access control
Azure Role-based access control
An Azure service that provides fine-grained access management for Azure resources, enabling you to grant users only the rights they need to perform their jobs.
708 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Stanislav Zhelyazkov 21,851 Reputation points MVP
    2024-04-24T13:30:24.9933333+00:00

    Hi,

    You need Policy Contributor role assigned to the user or the group at the Root Management group.

    Management groups are resource at tenant scope and above the subscription scope.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.