SHD / MC Checker

MC1409305 | Microsoft Entra: Blocking new assignments to partner tier support roles



MC1409305 | Microsoft Entra: Blocking new assignments to partner tier support roles

Classification planForChange
Last Updated 06/29/2026 22:06:48
Start Time 06/29/2026 22:06:36
End Time 09/24/2026 07:00:00
Message Content

[What and Why]

As part of ongoing role lifecycle management in Microsoft Entra, we will block new assignments to the Partner Tier1 Support and Partner Tier2 Support roles. These roles are no longer intended for use and are being retired. This change supports improved security and clearer role usage by encouraging the use of least-privilege roles.

[Rollout Schedule]

  • Global: Beginning August 3, 2026, and expected to complete by August 24, 2026

[Impact on Your Organization]

Who is affected

  •  Admins who manage role assignments in Microsoft Entra, including those using CSP or GDAP delegated access scenarios

Platforms/Services

  •  Microsoft Entra ID across portals, APIs, and automation workflows

What will happen

  • New assignments to Partner Tier1 Support and Partner Tier2 Support roles will be blocked.
  • This change is part of the retirement process for these roles.
  • If your organization does not use these roles, this change has no operational impact.
  • Attempts to assign these roles will fail with HTTP 400 (Request_BadRequest), indicating that assignments are no longer allowed.
  • Existing role assignments will continue to work without changes.
  • Removal of existing assignments will continue to work.
  • No other roles in Microsoft Entra are affected.

[Action Required/Recommendations]

  • No action is required if your organization does not use these roles.
  • If you currently use these roles, review and update any scripts, automation, or workflows that assign them.
  • For most scenarios, User Administrator is the closest replacement.
  • Replace usage with appropriate alternatives such as:
    • User Administrator
    • Helpdesk Administrator
    • Groups Administrator
    • License Administrator
    • Domain Name Administrator
  • Consider creating a custom role aligned to least privilege requirements if needed.
  • Review CSP or GDAP delegated admin configurations for use of these roles.
  • Update internal documentation and admin guidance as appropriate.
  • Contact Microsoft Support if you need help identifying a replacement role.

Learn more: 

[Compliance considerations]

No compliance considerations identified, review as appropriate for your organization.

Machine Translation

【何となぜ】

Microsoft Entraの継続的な役割ライフサイクル管理の一環として、パートナーTier1サポートおよびパートナーTier2サポートの役割への新規割り当てをブロックします。これらの役割は現在は使用を目的とせず、廃止される予定です。この変更により、最小権限ロールの使用を促進することで、セキュリティの向上と役割の明確な利用が促進されます。

[展開スケジュール]

  • グローバル:2026年8月3日開始、2026年8月24日までに完了予定

[組織への影響]

影響を受ける人物

  •   Microsoft Entraで役割割り当てを管理する管理者(CSPやGDAPの委任アクセスシナリオを含む)

プラットフォーム/サービス

  •  Microsoft Entra ID はポータル、API、自動化ワークフローにまたがっています

何が起こるのか

  • パートナーTier1サポートおよびパートナーTier2サポートの役割への新規割り当てはブロックされます。
  • この変更はこれらの職種の退職プロセスの一環です。
  • もし組織がこれらの役割を活用していなければ、この変更は運用上の影響を伴いません。
  • これらの役割の割り当ては HTTP 400(Request_BadRequest)で失敗し、割り当てが許可されていないことを示します。
  • 既存の役割割り当ては変更なしで引き続き機能します。
  • 既存の割り当ての削除は引き続き有効です。
  • Microsoft Entraの他のロールには影響はありません。

[行動が必要/提言]

  • 組織がこれらの役割を活用していなければ、何らかの対応は不要です。
  • 現在これらの役割を使っている場合は、それらに割り当てられたスクリプト、自動化、ワークフローを必ず確認・更新してください。
  • ほとんどのシナリオでは、 User Administrator が最も近い代替手段です。
  • 適切な代替手段に置き換えてください。
    • ユーザー管理者
    • ヘルプデスク管理者
    • グループ管理者
    • ライセンス管理者
    • ドメインネーム管理者
  • 必要に応じて、最小権限要件に合わせたカスタムロールを作成することも検討してください。
  • これらの役割を使用するためにCSPまたはGDAPの委任管理者設定を確認してください。
  • 内部ドキュメントや管理ガイダンスを適切に更新してください。
  • 代替役の特定が必要な場合は、Microsoftサポートに連絡してください。

詳しくはこちら: 

[コンプライアンスの考慮事項]

コンプライアンス上の懸念事項は特定されず、組織に応じてレビューしてください。