Skip to main content

← Back to the article

On September 11, 2026, three separately authenticated users exercised these operations through delegated Microsoft Graph v1.0 using the same temporary client application. Each token identified the intended actor, carried the same delegated scopes, and declared the expected test role plus the default directory-user role. A later active-assignment snapshot showed one expected direct role per operator. The initial directory-role eligibility read failed (403); a later read-only audit resolved that coverage gap and returned zero directory-role eligibility instances. PIM eligibility for group membership or ownership remains outside coverage.

Target and operationSecurity AdministratorEntra SOC Identity ResponderSecurity Operator
Ordinary user: disableState change verifiedState change verifiedState change verified
Ordinary user: enableState change verifiedState change verifiedState change verified
Ordinary user: revoke sessionsAPI accepted; timestamp advancedAPI accepted; timestamp advancedAPI accepted; timestamp advanced
Ordinary user: reset passwordAPI accepted; audit successAPI accepted; audit successAPI accepted; audit success
Global Reader: disableDenied (403)Denied (403)Denied (403)
Global Reader: enable from disabledDenied (403)Effect unverified (204)Denied (403)
Global Reader: revoke sessionsDenied (403)Denied (403)Denied (403)
Global Reader: reset passwordDenied (403)Denied (403)Denied (403)

β€œAPI accepted” is deliberately narrower than an end-to-end outcome. Revocation returned HTTP 200 with true, and the session-valid-from timestamp advanced. No active browser session or refresh-token rejection was tested. Password resets returned HTTP 204 and had successful password-reset audit records; nobody signed in using the new passwords.

Why the Global Reader enable result stays unresolved

An initial enable request returned 204 for all three roles while the target was already enabled. Those no-op responses are not authority evidence.

The follow-up started with the disposable Global Reader account disabled. Security Administrator and Security Operator received 403. SOC Identity Responder received 204, but the account remained disabled. A repeat established three disabled-state precondition reads, then eleven subsequent reads that all remained false over 21.483 seconds from first to last observation. The provisioning administrator restored the account after that observation window. This does not establish a role-boundary bypass or a successful enable operation.

Independent audit attribution

The final audit snapshot was collected at 23:43:48 UTC and contained 85 fixture-related records. None of the audit correlationId values matched the recorded client or service request IDs. Corroboration therefore uses the initiating user, target user, and recorded operation time window; it is not exact request-ID correlation.

All three operators’ ordinary-user disable, enable, revocation, and reset requests had corresponding successful actor/target/time-matched audit events in the final snapshot. Security Operator’s successful Enable account event at 23:38:17.4640339 UTC records false to true, corroborating the earlier state reads.

The earlier 23:39:59 UTC, 75-record snapshot did not yet contain that Security Operator enable event; the final snapshot did. The earlier absence was a snapshot limitation, not evidence that the observed state change failed.

For the longer SOC Identity Responder follow-up, the audit records show the provisioning administrator disabled the Global Reader target at 23:36:55.3338545 UTC and enabled it at 23:37:20.2595818 UTC. The eleven false-state observations occurred between 23:36:58.4657037 and 23:37:19.9491599 UTC. No SOC-attributed event for that target appeared in either follow-up window. Audit ingestion can lag, so a follow-up query of the directory audit log on September 12, 2026 at 14:45 UTC, about fifteen hours later, rechecked the same window: it returned every record from the final snapshot plus the later cleanup events, and still no SOC Identity Responder event for the Global Reader target.

Scope of the conclusion

These observations support a comparison of three roles against an ordinary user and a Global Reader administrator in this tenant. They do not establish behavior for all privileged roles, every tenant, or the Defender portal. Assignment and eligibility results are point-in-time observations, not a complete historical privilege inventory.

The later read-only audit, with run timestamp September 12, 2026 at 00:07:46 UTC (September 11 locally), completed all eight Graph collection scans and all five principal checks. It returned zero directory-role eligibility instances; the five principals’ transitive active-role, group-membership, user-state, and directory-eligibility checks completed. Only the administrative reader received additional read permissions; the operator action scopes were unchanged. This does not extend coverage to PIM eligibility for group membership or ownership.

No passwords, TAPs, access tokens, user names, tenant IDs, app IDs, target IDs, or request identifiers are included here. The companion JSON preserves sanitized observations, evidence limits, source filenames, and source-file checksums.